Cisco Anomaly Guard Module Web-Based Manager Configuration Guide (Software Version 6.1 and 6.1-XG)
Index

Table Of Contents

Symbols - A - B - C - D - E - F - G - H - I - J - L - M - N - O - P - R - S - T - U - V - W - Z

Index

Symbols

# (number sign) 10-24, 10-27

* (wildcard) 10-24, 10-26

A

AAA services 3-2

activation extent

entire zone 4-9

IP address only 4-9

activation interface

by IP address 4-9

by packet 4-8

active dynamic filters 10-12

analyzing traffic flow 10-15

analyzing zone traffic problems 10-15

anomaly detection engine memory usage 10-9

anomaly flow, common characteristics 10-24

anti-spoofing internal errors 10-36

attack

statistics 10-22

summary 10-19

types 10-20, 10-26

attack report

deleting 10-30

dropped/bounced packets 10-22

exporting 10-29

report details 10-21

viewing current attack details 10-21

viewing past attack details 10-21

zone 10-20

attacks summary report 10-18

auth packet types 8-4, 10-33

automatic learning, configuring 7-8

automatic protect operation mode 4-6, 4-7, 9-3

B

bad packets to proxy addresses 10-36

bandwidth limited link templates 4-5

banner, configuring login 2-3

base zone 7-17

base zone services

adding 7-19

copying policy parameters to the base zone 7-20

deleting 7-19

Berkley Packet Filter 5-9

burst 4-7

bypass filter

adding 5-5

definition 5-2

deleting 5-6

C

capture and view parameters

packet-dump capture analysis 11-9

capture parameter

packet-dump capture analysis 11-10

changing another user password 3-5

changing your password 3-5

client attack 10-20, 10-26

compared zone 7-17

concurrent connections 10-32

constructing policies 7-2

copy wbm-logo command 2-3

counters

clearing Device 10-5

clearing zone 10-14

dropped 10-4, 10-6, 10-14, 10-17, 10-22

forwarded 10-22

legitimate 10-4, 10-6, 10-14, 10-17

malicious 10-4, 10-6, 10-14, 10-17

received 10-4, 10-6, 10-14, 10-17, 10-22

replied 10-4, 10-6, 10-14, 10-17, 10-22

spoofed 10-4, 10-6, 10-14, 10-17

zone 10-14

create a zone

using an existing zone as a template 4-10

using a predefined zone template 4-5

D

DDoS

nonspoofed attacks 1-3

overview 1-3

spoofed attacks 1-3

zombies 1-3

detected anomalies

types 10-20, 10-24

viewing 10-23

viewing details 10-25

Devicecounters, clearing 10-5

device resources, monitoring 10-8

diagnostics, viewing 10-4

DNS

drop statistics 10-35

policy templates 6-1

dropped/bounced packets 10-22

drop statistics 10-34

dst traffic characteristics 8-5

dynamic filter

actions 9-11

active 10-12

adding 9-10

deactivating 9-8

definition 5-2

deleting 9-12

fields 9-11

pending 9-15, 10-12

preventing production of 9-12

recommendations 9-15

table 9-9

viewing 9-8

dynamic filters

overview 9-8

E

event log

Guard 10-7

zone 10-18

extent of zone protection 4-3

F

filter actions

dynamic filters 9-9, 9-11

user filters 5-4

filter overview

bypass 5-2

dynamic 5-2

flex-content 5-2

user 5-2

filter-rate termination threshold 4-8

flex-content filter

adding 5-10

configuring 5-7

definition 5-2

deleting 5-12

expression 5-7

pattern 5-10

fragments 10-24

G

general attack information 10-22

GUARD_LINK zone templates 4-5

GUARD_VOIP zone template 4-6

H

HTTP

policy template 6-2

type of detected anomaly 10-24

zombies 10-28, 10-30

zombies list 10-30

hybrid, type of mitigated attack 10-20

I

icons 1-6

information area 1-6

in packet types 10-33

interactive protect operation mode 4-6, 4-7, 9-3

IP address, configuring zone 4-10, 4-11

IP scan 6-2, 10-24

IP summarization 11-2, 11-4

packet-dump capture analysis 11-9

IP threshold configuration 8-9

J

Java 2 Runtime Environment (JRE), installing 1-2

L

land attack 10-36

learning process

overview 7-1

performing 7-3

phases 7-2

policy construction phase

accepting the results 7-4

overview 7-2

starting 7-4

stopping 7-4

threshold tuning phase

accepting the results 7-6

overview 7-2

starting 7-5

stopping 7-7

login banner, configuring 2-3

logo, adding WBM 2-3

M

main menu bar 1-5

malformed packets 10-20, 10-23, 10-26, 10-36

malicious-rate

detection threshold 4-7

termination threshold 4-8

marking zone policies tuned or untuned 7-12

memory usage, anomaly detection engine 10-9

mitigated attack

action flow 10-26

anomaly flow 10-26

attack types 10-26

viewing 10-26

viewing details 10-27

N

navigation area 1-5

new recommendations 9-15

non DNS drop statistics 10-36

nonspoofed attacks 1-3

O

on-demand protection

activating 9-4

overview 9-2

operation modes

automatic protect 4-6, 4-7

interactive protect 4-6, 4-7

other protocols

drop statistics 10-35

policy template 6-2

out_pkts packet types 10-33

P

packet-dump capture

automatic capture

disabling 11-4

enabling 11-2

file

deleting 11-16

exporting 11-14

importing 11-15

renaming 11-13

manual capture

starting 11-5

stopping 11-6

overview 11-1

packet-dump capture analysis

capture and view parameters 11-9

capture parameter 11-10

IP summarization 11-9

packets

dropped/bounced 10-22

malformed 10-23

packet type

auth 8-4

out_pkts 10-33

pkts 8-4, 10-33

reqs 8-4

syns 8-4

unauth_pkts 8-4, 10-33

password

changing another user password 3-5

changing your password 3-5

pending dynamic filters

accepting 9-19

fields 9-17

in zone status table 10-12

number exceeds 1000 9-14

overview 9-15

pkts packet type 8-4, 10-33

policy

constructing 7-2

key 8-5

service 8-3

services

adding 8-11

deleting 8-12

statistics 10-31

types 8-4

policy construction phase

starting 7-3

stopping 7-4

policy statistics table, viewing 10-31

policy template

no proxy zones 6-3

other_protocols 6-2

overview 6-1

template types 6-1

types of templates 6-1

port scan 6-2, 10-24

privilege levels, moving between 3-6

protect

automatic operation mode 9-3

interactive operation mode 9-3

on-demand 9-2

Protect and Learn feature

activating 7-10

deactivating 7-11

overview 9-3

Protect feature

activating 9-4

deactivating 9-6

overview 9-3

protection activation methods 4-2

protection-end time 4-7

protection verification 9-6

proxy usage, displaying 10-13

R

rate 4-7

ratio, SYN to FIN/RST packets 10-32

recommendations, viewing new 9-15

redirect/zombie 9-11

replied IP summarization 11-2, 11-4

reqs packet type 8-4, 10-33

RTP/RTCP 4-6

S

service

adding 8-11

deleting 8-12

SIP

detected anomalies 10-24

drop statistics 10-36

policy template 6-2

spoofed statistics 10-37

zone template 4-6

snapshot

comparing two snapshots 7-17

learning process results 7-14

overview 7-13

zone configuration policies 7-14

spoofed attack 1-3, 10-20, 10-26

spoofed packets 10-23

src traffic characteristics 8-5, 10-34

status icons 1-6

status summary, zone 10-12

subzone

overview 4-3

reports 10-20

syn_by_fin packet type 10-33

syns packet types 8-4, 10-33

system requirements 1-1

T

TACACS+

AAA services 3-2

TCP

detected anomalies 10-24

drop statistics 10-35

policy templates 6-2

template, zone 4-5

threshold

configuring IP threshold 8-9

filter-rate termination 4-8

malicious-rate termination 4-8

tuning 7-2

threshold tuning phase

accepting results 7-6

overview 7-2

starting 7-5

stopping 7-7

traffic rate 10-31

troubleshooting WBM connection 2-2

tuning thresholds 7-2, 7-5

U

UDP

drop statistics 10-35

policy template 6-2

unauth_pkts packet type 8-4, 10-33

user authentication methods 3-2

user filter

actions 5-4

adding 5-3

configuring 5-3

deleting 5-5

overview 5-2

user interface 1-4

user privilege levels, moving between 3-6

user profile

changing another user password 3-5

changing your password 3-5

configuring on a TACACS+ server 3-6

creating 3-3

deleting 3-4

displaying the list of users 3-3

preconfigured user profiles 3-2

V

viewing

attack reports 10-18, 10-21

diagnostics 10-4

drop statistics 10-34

dynamic filters 9-8

pending dynamic filters 9-17

policy configuration differences 7-17

policy statistics 10-31

recommendations 9-15

zone status 9-6

Voice over IP

See VoIP

VoIP

detected anomalies 10-24

drop statistics 10-36

policy template 6-2

spoofed statistics 10-37

zone template 4-6

W

WBM

enabling service 2-1

launching 2-2

setting up 2-1

troubleshooting connection 2-2

WBM logo, adding 2-3

Z

zombie

detected 10-28

list 10-30

mitigated attack type 10-20, 10-26

overview 1-3

zone

counters

clearing 10-14

viewing 10-14

viewing in real time 10-17

create

methods 4-2

using another zone 4-10

using a predefined zone template 4-5

delete 4-13

diagnostic tools 10-13

event log 10-7, 10-18

extent of protection 4-3

icons 1-6

IP address

adding 4-10

deleting 4-11

learning 7-1

operation mode

changing to automatic 9-13

changing to interactive 9-14

overview 9-13

taking action when pending filters exceed 1000 9-14

overview 4-1

policies

adding an IP address and threshold 8-10

adding a service 8-11

deleting a service 8-12

tuned 7-12

untuned 7-12

viewing 8-2

protection

activating 9-4

deactivating 9-6

extent 4-3

on-demand, activating 9-4

on-demand overview 9-2

options 9-2

Protect and Learn feature 9-3

Protect feature 9-3

verifying 9-6

protection activation methods 4-2

recent events table 10-12

status

status bar 10-11

status table 10-12

viewing 10-10

status summary 10-12

subzone 4-3

template

predefined 4-2

types 4-5

traffic rate graph 10-11

zone proxy usage, displaying 10-13