D-Link DFL-260E User Manual page 330

Network security firewall netdefendos version 2.27.03
Hide thumbs Also See for DFL-260E:
Table of Contents

Advertisement

6.5.8. SMTP Log Receiver for IDP
Events
Specify the Rule Action:
gw-world:/> cc IDPRule IDPMailSrvRule
gw-world:/IDPMailSrvRule> add IDPRuleAction Action=Protect
Web Interface
Create an IDP Rule:
This IDP rule is called IDPMailSrvRule, and applies to the SMTP service. Source Interface and Source Network
define where traffic is coming from, in this example, the external network. The Destination Interface and
Destination Network define where traffic is directed to, in this case the mail server. Destination Network should
therefore be set to the object defining the mail server.
1.
Go to IDP > IDP Rules > Add > IDP Rule
2.
Now enter:
Name: IDPMailSrvRule
Service: smtp
Also inspect dropped packets: In case all traffic matching this rule should be scanned (this also means
traffic that the main rule set would drop), the Protect against insertion/evasion attacks checkbox
should be checked, which is the case in this example.
Source Interface: wan
Source Network: wannet
Destination Interface: dmz
Destination Network: ip_mailserver
Click OK
Specify the Action:
An action is now defined, specifying what signatures the IDP should use when scanning data matching the rule,
and what NetDefendOS should do when a possible intrusion is detected. In this example, intrusion attempts will
cause the connection to be dropped, so Action is set to Protect. The Signatures option is set to
IPS_MAIL_SMTP in order to use signatures that describe attacks from the external network that are based on the
SMTP protocol.
1.
Select the Rule Action tab for the IDP rule
2.
Now enter:
Action: Protect
Signatures: IPS_MAIL_SMTP
Click OK
If logging of intrusion attempts is desired, this can be configured by clicking in the Rule Actions tab when
creating an IDP rule and enabling logging. The Severity should be set to All in order to match all SMTP attacks.
In summary, the following will occur: If traffic from the external network to the mail server occurs, IDP will be
activated. If traffic matches any of the signatures in the IPS_MAIL_SMTP signature group, the connection will be
dropped, thus protecting the mail server.
Using Individual Signatures
The preceding example uses an entire IDP group name when enabling IDP. However, it is possible
SourceNetwork=wannet
DestinationInterface=dmz
DestinationNetwork=ip_mailserver
Name=IDPMailSrvRule
IDPServity=All Signatures=IPS_MAIL_SMTP
330
Chapter 6. Security Mechanisms

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents