Table Of Contents
Symbols - A - B - C - D - E - F - G - H - I - J - L - M - N - O - P - R - S - T - U - V - W - Z
Index
Symbols
# (number sign) 10-24, 10-26
* (wildcard) 10-23, 10-25
A
AAA services 3-2
activation extent
entire zone 4-9
IP address only 4-9
activation interface
by IP address 4-9
by packet 4-8
active dynamic filters 10-11
analyzing traffic flow 10-14
analyzing zone traffic problems 10-14
anomaly detection engine memory usage 10-8
anomaly flow, common characteristics 10-23
anti-spoofing internal errors 10-35
attack
statistics 10-21
summary 10-18
types 10-19, 10-25
attack report
deleting 10-29
dropped/bounced packets 10-21
exporting 10-28
report details 10-20
viewing current attack details 10-20
viewing past attack details 10-20
zone 10-19
attacks summary report 10-17
auth packet types 8-4, 10-32
automatic learning, configuring 7-8
automatic protect operation mode 4-6, 4-7, 9-3
B
bad packets to proxy addresses 10-35
bandwidth limited link templates 4-5
banner, configuring login 2-3
base zone 7-17
base zone services
adding 7-19
copying policy parameters to the base zone 7-20
deleting 7-19
Berkley Packet Filter 5-9
burst 4-7
bypass filter
adding 5-5
definition 5-2
deleting 5-6
C
changing another user password 3-5
changing your password 3-5
client attack 10-19, 10-25
compared zone 7-17
concurrent connections 10-31
constructing policies 7-2
copy wbm-logo command 2-3
counters
clearing Device 10-4
clearing zone 10-13
dropped 10-4, 10-5, 10-13, 10-16, 10-21
forwarded 10-21
legitimate 10-4, 10-5, 10-13, 10-16
malicious 10-4, 10-5, 10-13, 10-16
received 10-4, 10-5, 10-13, 10-16, 10-21
replied 10-4, 10-5, 10-13, 10-16, 10-21
spoofed 10-4, 10-5, 10-13, 10-16
zone 10-13
create a zone
using an existing zone as a template 4-10
using a predefined zone template 4-5
D
DDoS
nonspoofed attacks 1-3
overview 1-3
spoofed attacks 1-3
zombies 1-3
detected anomalies
types 10-19, 10-23
viewing 10-22
viewing details 10-24
device resources, monitoring 10-7
diagnostics, viewing 10-3
DNS
drop statistics 10-34
policy templates 6-1
dropped/bounced packets 10-21
drop statistics 10-33
dst traffic characteristics 8-5
dynamic filter
actions 9-11
active 10-11
adding 9-10
deactivating 9-7
definition 5-2
deleting 9-12
fields 9-10
pending 9-14, 10-11
preventing production of 9-12
recommendations 9-14
table 9-8
viewing 9-8
dynamic filters
overview 9-7
E
event log
Guard 10-6
zone 10-17
extent of zone protection 4-3
F
filter actions
dynamic filters 9-9, 9-11
user filters 5-4
filter overview
bypass 5-2
dynamic 5-2
flex-content 5-2
user 5-1
filter-rate termination threshold 4-8
flex-content filter
adding 5-10
configuring 5-7
definition 5-2
deleting 5-12
expression 5-7
pattern 5-10
fragments 10-23
G
general attack information 10-21
GUARD_LINK zone templates 4-5
GUARD_VOIP zone template 4-6
Guard counters, clearing 10-4
H
HTTP
policy template 6-2
type of detected anomaly 10-23
zombies 10-27, 10-29
zombies list 10-29
hybrid, type of mitigated attack 10-19
I
icons 1-6
information area 1-6
in packet types 10-32
interactive protect operation mode 4-6, 4-7, 9-3
IP address, configuring zone 4-10, 4-11
IP scan 6-2, 10-23
IP summarization 11-2, 11-4
packet-dump capture analysis 11-9
IP threshold configuration 8-9
J
Java 2 Runtime Environment (JRE), installing 1-2
L
land attack 10-35
learning process
overview 7-1
performing 7-3
phases 7-2
policy construction phase
accepting the results 7-4
overview 7-2
starting 7-3
stopping 7-4
threshold tuning phase
accepting the results 7-5
overview 7-2
starting 7-5
stopping 7-6
login banner, configuring 2-3
logo, adding WBM 2-3
M
main menu bar 1-5
malformed packets 10-19, 10-22, 10-25, 10-35
malicious-rate
detection threshold 4-8
termination threshold 4-8
marking zone policies tuned or untuned 7-12
memory usage, anomaly detection engine 10-8
mitigated attack
action flow 10-25
anomaly flow 10-25
attack types 10-25
viewing 10-25
viewing details 10-26
N
navigation area 1-5
new recommendations 9-15
non DNS drop statistics 10-35
nonspoofed attacks 1-3
O
on-demand protection
activating 9-4
overview 9-2
operation modes
automatic protect 4-6, 4-7
interactive protect 4-6, 4-7
other protocols
drop statistics 10-34
policy template 6-2
out_pkts packet types 10-32
P
packet-dump
automatic
activating 11-2
packet-dump capture
automatic capture
disabling 11-4
enabling 11-2
file
deleting 11-16
exporting 11-14
importing 11-15
renaming 11-13
manual capture
starting 11-5
stopping 11-6
overview 11-1
packet-dump capture analysis
IP summarization 11-9
packets
dropped/bounced 10-21
malformed 10-22
packet type
auth 8-4
out_pkts 10-32
pkts 8-4, 10-32
reqs 8-4
syns 8-4
unauth_pkts 8-4, 10-32
password
changing another user password 3-5
changing your password 3-5
pending dynamic filters
accepting 9-18
fields 9-17
in zone status table 10-11
number exceeds 1000 9-14
overview 9-14
pkts packet type 8-4, 10-32
policy
constructing 7-2
key 8-5
service 8-3
services
adding 8-11
deleting 8-12
statistics 10-30
types 8-4
policy construction phase
starting 7-3
stopping 7-4
policy statistics table, viewing 10-30
policy template
no proxy zones 6-3
other_protocols 6-2
overview 6-1
template types 6-1
types of templates 6-1
port scan 6-2, 10-23
privilege levels, moving between 3-6
protect
automatic operation mode 9-3
interactive operation mode 9-3
on-demand 9-2
Protect and Learn feature
activating 7-10
deactivating 7-11
overview 9-2
Protect feature
activating 9-3
deactivating 9-6
overview 9-2
protection activation methods 4-2
protection-end time 4-7
protection verification 9-5
proxy usage, displaying 10-12
R
rate 4-7
ratio, SYN to FIN/RST packets 10-31
recommendations, viewing new 9-15
redirect/zombie 9-11
replied IP summarization 11-2, 11-4
reqs packet type 8-4, 10-32
RTP/RTCP 4-6
S
service
adding 8-11
deleting 8-12
SIP
detected anomalies 10-23
drop statistics 10-35
policy template 6-2
spoofed statistics 10-36
zone template 4-6
snapshot
comparing two snapshots 7-17
learning process results 7-14
overview 7-13
zone configuration policies 7-14
spoofed attack 1-3, 10-19, 10-25
spoofed packets 10-22
src traffic characteristics 8-5, 10-33
status icons 1-6
status summary, zone 10-11
subzone
overview 4-3
reports 10-19
syn_by_fin packet type 10-32
syns packet types 8-4, 10-32
system requirements 1-1
T
TACACS+
AAA services 3-2
TCP
detected anomalies 10-23
drop statistics 10-34
policy templates 6-2
template, zone 4-5
threshold
configuring IP threshold 8-9
filter-rate termination 4-8
malicious-rate termination 4-8
tuning 7-2
threshold tuning phase
accepting results 7-5
overview 7-2
starting 7-5
stopping 7-6
traffic rate 10-31
troubleshooting WBM connection 2-2
tuning thresholds 7-2, 7-5
U
UDP
drop statistics 10-34
policy template 6-2
unauth_pkts packet type 8-4, 10-32
user authentication methods 3-2
user filter
actions 5-4
adding 5-2
configuring 5-2
deleting 5-5
overview 5-1
user interface 1-4
user privilege levels, moving between 3-6
user profile
changing another user password 3-5
changing your password 3-5
configuring on a TACACS+ server 3-6
creating 3-3
deleting 3-4
displaying the list of users 3-3
preconfigured user profiles 3-2
V
viewing
attack reports 10-17, 10-20
diagnostics 10-3
drop statistics 10-33
dynamic filters 9-8
pending dynamic filters 9-16
policy configuration differences 7-17
policy statistics 10-30
recommendations 9-15
zone status 9-5
Voice over IP
See VoIP
VoIP
detected anomalies 10-23
drop statistics 10-35
policy template 6-2
spoofed statistics 10-36
zone template 4-6
W
WBM
enabling service 2-1
launching 2-2
setting up 2-1
troubleshooting connection 2-2
WBM logo, adding 2-3
Z
zombie
detected 10-27
list 10-29
mitigated attack type 10-19, 10-25
overview 1-3
zone
counters
clearing 10-13
viewing 10-13
viewing in real time 10-16
create
methods 4-2
using another zone 4-10
using a predefined zone template 4-5
delete 4-13
diagnostic tools 10-12
event log 10-6, 10-17
extent of protection 4-3
icons 1-6
IP address
adding 4-10
deleting 4-11
learning 7-1
operation mode
changing to automatic 9-13
changing to interactive 9-13
overview 9-13
taking action when pending filters exceed 1000 9-14
overview 4-1
policies
adding an IP address and threshold 8-10
adding a service 8-11
deleting a service 8-12
tuned 7-12
untuned 7-12
viewing 8-2
protection
activating 9-3
deactivating 9-6
extent 4-3
on-demand, activating 9-4
on-demand overview 9-2
options 9-1
Protect and Learn feature 9-2
Protect feature 9-2
verifying 9-5
protection activation methods 4-2
recent events table 10-11
status
status bar 10-10
status table 10-11
viewing 10-9
status summary 10-11
subzone 4-3
template
predefined 4-2
types 4-5
traffic rate graph 10-10
zone proxy usage, displaying 10-12