Cisco Guard Web-Based Manager Configuration Guide (Software Version 6.1)
Index

Table Of Contents

Symbols - A - B - C - D - E - F - G - H - I - J - L - M - N - O - P - R - S - T - U - V - W - Z

Index

Symbols

# (number sign) 10-24, 10-26

* (wildcard) 10-23, 10-25

A

AAA services 3-2

activation extent

entire zone 4-9

IP address only 4-9

activation interface

by IP address 4-9

by packet 4-8

active dynamic filters 10-11

analyzing traffic flow 10-14

analyzing zone traffic problems 10-14

anomaly detection engine memory usage 10-8

anomaly flow, common characteristics 10-23

anti-spoofing internal errors 10-35

attack

statistics 10-21

summary 10-18

types 10-19, 10-25

attack report

deleting 10-29

dropped/bounced packets 10-21

exporting 10-28

report details 10-20

viewing current attack details 10-20

viewing past attack details 10-20

zone 10-19

attacks summary report 10-17

auth packet types 8-4, 10-32

automatic learning, configuring 7-8

automatic protect operation mode 4-6, 4-7, 9-3

B

bad packets to proxy addresses 10-35

bandwidth limited link templates 4-5

banner, configuring login 2-3

base zone 7-17

base zone services

adding 7-19

copying policy parameters to the base zone 7-20

deleting 7-19

Berkley Packet Filter 5-9

burst 4-7

bypass filter

adding 5-5

definition 5-2

deleting 5-6

C

changing another user password 3-5

changing your password 3-5

client attack 10-19, 10-25

compared zone 7-17

concurrent connections 10-31

constructing policies 7-2

copy wbm-logo command 2-3

counters

clearing Device 10-4

clearing zone 10-13

dropped 10-4, 10-5, 10-13, 10-16, 10-21

forwarded 10-21

legitimate 10-4, 10-5, 10-13, 10-16

malicious 10-4, 10-5, 10-13, 10-16

received 10-4, 10-5, 10-13, 10-16, 10-21

replied 10-4, 10-5, 10-13, 10-16, 10-21

spoofed 10-4, 10-5, 10-13, 10-16

zone 10-13

create a zone

using an existing zone as a template 4-10

using a predefined zone template 4-5

D

DDoS

nonspoofed attacks 1-3

overview 1-3

spoofed attacks 1-3

zombies 1-3

detected anomalies

types 10-19, 10-23

viewing 10-22

viewing details 10-24

device resources, monitoring 10-7

diagnostics, viewing 10-3

DNS

drop statistics 10-34

policy templates 6-1

dropped/bounced packets 10-21

drop statistics 10-33

dst traffic characteristics 8-5

dynamic filter

actions 9-11

active 10-11

adding 9-10

deactivating 9-7

definition 5-2

deleting 9-12

fields 9-10

pending 9-14, 10-11

preventing production of 9-12

recommendations 9-14

table 9-8

viewing 9-8

dynamic filters

overview 9-7

E

event log

Guard 10-6

zone 10-17

extent of zone protection 4-3

F

filter actions

dynamic filters 9-9, 9-11

user filters 5-4

filter overview

bypass 5-2

dynamic 5-2

flex-content 5-2

user 5-1

filter-rate termination threshold 4-8

flex-content filter

adding 5-10

configuring 5-7

definition 5-2

deleting 5-12

expression 5-7

pattern 5-10

fragments 10-23

G

general attack information 10-21

GUARD_LINK zone templates 4-5

GUARD_VOIP zone template 4-6

Guard counters, clearing 10-4

H

HTTP

policy template 6-2

type of detected anomaly 10-23

zombies 10-27, 10-29

zombies list 10-29

hybrid, type of mitigated attack 10-19

I

icons 1-6

information area 1-6

in packet types 10-32

interactive protect operation mode 4-6, 4-7, 9-3

IP address, configuring zone 4-10, 4-11

IP scan 6-2, 10-23

IP summarization 11-2, 11-4

packet-dump capture analysis 11-9

IP threshold configuration 8-9

J

Java 2 Runtime Environment (JRE), installing 1-2

L

land attack 10-35

learning process

overview 7-1

performing 7-3

phases 7-2

policy construction phase

accepting the results 7-4

overview 7-2

starting 7-3

stopping 7-4

threshold tuning phase

accepting the results 7-5

overview 7-2

starting 7-5

stopping 7-6

login banner, configuring 2-3

logo, adding WBM 2-3

M

main menu bar 1-5

malformed packets 10-19, 10-22, 10-25, 10-35

malicious-rate

detection threshold 4-8

termination threshold 4-8

marking zone policies tuned or untuned 7-12

memory usage, anomaly detection engine 10-8

mitigated attack

action flow 10-25

anomaly flow 10-25

attack types 10-25

viewing 10-25

viewing details 10-26

N

navigation area 1-5

new recommendations 9-15

non DNS drop statistics 10-35

nonspoofed attacks 1-3

O

on-demand protection

activating 9-4

overview 9-2

operation modes

automatic protect 4-6, 4-7

interactive protect 4-6, 4-7

other protocols

drop statistics 10-34

policy template 6-2

out_pkts packet types 10-32

P

packet-dump

automatic

activating 11-2

packet-dump capture

automatic capture

disabling 11-4

enabling 11-2

file

deleting 11-16

exporting 11-14

importing 11-15

renaming 11-13

manual capture

starting 11-5

stopping 11-6

overview 11-1

packet-dump capture analysis

IP summarization 11-9

packets

dropped/bounced 10-21

malformed 10-22

packet type

auth 8-4

out_pkts 10-32

pkts 8-4, 10-32

reqs 8-4

syns 8-4

unauth_pkts 8-4, 10-32

password

changing another user password 3-5

changing your password 3-5

pending dynamic filters

accepting 9-18

fields 9-17

in zone status table 10-11

number exceeds 1000 9-14

overview 9-14

pkts packet type 8-4, 10-32

policy

constructing 7-2

key 8-5

service 8-3

services

adding 8-11

deleting 8-12

statistics 10-30

types 8-4

policy construction phase

starting 7-3

stopping 7-4

policy statistics table, viewing 10-30

policy template

no proxy zones 6-3

other_protocols 6-2

overview 6-1

template types 6-1

types of templates 6-1

port scan 6-2, 10-23

privilege levels, moving between 3-6

protect

automatic operation mode 9-3

interactive operation mode 9-3

on-demand 9-2

Protect and Learn feature

activating 7-10

deactivating 7-11

overview 9-2

Protect feature

activating 9-3

deactivating 9-6

overview 9-2

protection activation methods 4-2

protection-end time 4-7

protection verification 9-5

proxy usage, displaying 10-12

R

rate 4-7

ratio, SYN to FIN/RST packets 10-31

recommendations, viewing new 9-15

redirect/zombie 9-11

replied IP summarization 11-2, 11-4

reqs packet type 8-4, 10-32

RTP/RTCP 4-6

S

service

adding 8-11

deleting 8-12

SIP

detected anomalies 10-23

drop statistics 10-35

policy template 6-2

spoofed statistics 10-36

zone template 4-6

snapshot

comparing two snapshots 7-17

learning process results 7-14

overview 7-13

zone configuration policies 7-14

spoofed attack 1-3, 10-19, 10-25

spoofed packets 10-22

src traffic characteristics 8-5, 10-33

status icons 1-6

status summary, zone 10-11

subzone

overview 4-3

reports 10-19

syn_by_fin packet type 10-32

syns packet types 8-4, 10-32

system requirements 1-1

T

TACACS+

AAA services 3-2

TCP

detected anomalies 10-23

drop statistics 10-34

policy templates 6-2

template, zone 4-5

threshold

configuring IP threshold 8-9

filter-rate termination 4-8

malicious-rate termination 4-8

tuning 7-2

threshold tuning phase

accepting results 7-5

overview 7-2

starting 7-5

stopping 7-6

traffic rate 10-31

troubleshooting WBM connection 2-2

tuning thresholds 7-2, 7-5

U

UDP

drop statistics 10-34

policy template 6-2

unauth_pkts packet type 8-4, 10-32

user authentication methods 3-2

user filter

actions 5-4

adding 5-2

configuring 5-2

deleting 5-5

overview 5-1

user interface 1-4

user privilege levels, moving between 3-6

user profile

changing another user password 3-5

changing your password 3-5

configuring on a TACACS+ server 3-6

creating 3-3

deleting 3-4

displaying the list of users 3-3

preconfigured user profiles 3-2

V

viewing

attack reports 10-17, 10-20

diagnostics 10-3

drop statistics 10-33

dynamic filters 9-8

pending dynamic filters 9-16

policy configuration differences 7-17

policy statistics 10-30

recommendations 9-15

zone status 9-5

Voice over IP

See VoIP

VoIP

detected anomalies 10-23

drop statistics 10-35

policy template 6-2

spoofed statistics 10-36

zone template 4-6

W

WBM

enabling service 2-1

launching 2-2

setting up 2-1

troubleshooting connection 2-2

WBM logo, adding 2-3

Z

zombie

detected 10-27

list 10-29

mitigated attack type 10-19, 10-25

overview 1-3

zone

counters

clearing 10-13

viewing 10-13

viewing in real time 10-16

create

methods 4-2

using another zone 4-10

using a predefined zone template 4-5

delete 4-13

diagnostic tools 10-12

event log 10-6, 10-17

extent of protection 4-3

icons 1-6

IP address

adding 4-10

deleting 4-11

learning 7-1

operation mode

changing to automatic 9-13

changing to interactive 9-13

overview 9-13

taking action when pending filters exceed 1000 9-14

overview 4-1

policies

adding an IP address and threshold 8-10

adding a service 8-11

deleting a service 8-12

tuned 7-12

untuned 7-12

viewing 8-2

protection

activating 9-3

deactivating 9-6

extent 4-3

on-demand, activating 9-4

on-demand overview 9-2

options 9-1

Protect and Learn feature 9-2

Protect feature 9-2

verifying 9-5

protection activation methods 4-2

recent events table 10-11

status

status bar 10-10

status table 10-11

viewing 10-9

status summary 10-11

subzone 4-3

template

predefined 4-2

types 4-5

traffic rate graph 10-10

zone proxy usage, displaying 10-12