Zyxel ZyWALL USG 300 [162/185] Zywall usg support notes

Zyxel ZyWALL USG 20 [162/185] Zywall usg support notes
ZyWALL USG Support Notes
162
All contents copyright (c) 2010 ZyXEL Communications Corporation.
none”.
J06. What are the major design differences in IDP in ZLD1.0x
and latest IDP/ADP in ZLD2.0x?
The following are 3 major differences made from ZLD2.0x 2000:
IDP-Inspects via. Signature
An IDP system can detect malicious or suspicious packets and respond
instantaneously. It is designed to detect pattern-based attacks.
The signature is designed for IDP in the purpose of detecting pattern-based attacks.
If a packet matches a signature, the action specified by the signature is taken. You can
change the default signature actions in the profile screens.
You can create custom signatures for new attacks or attacks peculiar to your network.
Custom signatures can also be saved to/from your computer so as to share with others.
ADP-Anomaly
An ADP (Anomaly, Detection and Prevention) system can detect malicious or
suspicious packets and respond instantaneously. It can detect:
Anomalies based on violations of protocol standards.
Abnormal flows such as port scans.
ADP on the ZyWALL protects against network-based intrusions. You can also create
your own custom ADP rules.
System Protection
System Protection System offers the ZyWALL ability to protect itself against
host-based intrusions. ZyXEL can prevent not only network intrusions but also
host-based instructions.
Zone to Zone Protection
A zone is a combination of ZyWALL interfaces for security. Traffic direction is
defined by the zone the traffic is coming from and the zone the traffic is going to.
The ZyWALL can inspect the traffic from different sources. Therefore, the
malicious/suspicious packets from WAN to LAN and the traffic coming from DMZ to

Содержание

Похожие устройства