Descriptions of Other Options

When configuring a signature set, you can also configure other protocol-related options. The available options may vary by different protocol types. This section describes options for specific protocols in detail.


DNS

Protocol anomaly detection: Specifies a check level for the protocol validity check of the signature set.


FTP

Action for brute-force: If the login attempts per minute fail for the times specified by the threshold, system will identify the attempts as an intrusion and take an action according to the configuration.

Protocol anomaly detection: Specifies a check level for the protocol validity check of the signature set.

Banner protection: Select the Enable check box to enable protection against FTP server banners.

Max command line length: Specifies a max length (including carriage return) for the FTP command line. The value range is 5 to 1024 bytes.

Max response line length: Specifies a max length for the FTP response line. The value range is 5 to 1024 bytes.


HTTP

Protocol anomaly detection: Specifies a check level for the protocol validity check of the signature set.

Banner protection: Select the Enable check box to enable protection against HTTP server banners.

Max URI length: Specifies a max URI length for the HTTP protocol. The value range is 64 to 4096 bytes.

Allowed methods: Specifies allowed HTTP method(s).

XSS check: Select the Enable check box to enable XSS check for the HTTP protocol.

SQL check: Select the Enable check box to enable SQL injection check for the HTTP protocol.

Command injection check: Select the Enable check box to enable command injection check for the HTTP protocol.


POP3

Action for brute-force: If the login attempts per minute fail for the times specified by the threshold, system will identify the attempts as an intrusion and take an action according to the configuration.

Protocol anomaly detection: Specifies a check level for the protocol validity check of the signature set.

Banner protection: Select the Enable check box to enable protection against POP3 server banners.

Max command line length: Specifies a max length (including carriage return) for the POP3 command line. The value range is 5 to 1024 bytes.

Max parameter length: Specifies a max length for the POP3 client command parameter. The value range is 8 to 256 bytes.

Max failure time: Specifies a max failure time (within one single POP3 session) for the POP3 server. The value range is 0 to 512 times.


SMTP

Action for brute-force: If the login attempts per minute fail for the times specified by the threshold, system will identify the attempts as an intrusion and take an action according to the configuration.

Protocol anomaly detection: Specifies a check level for the protocol validity check of the signature set.

Banner protection: Select the Enable check box to enable protection against SMTP server banners.

Max command line length: Specifies a max length (including carriage return) for the SMTP command line. The value range is 5 to 1024 bytes.

Max path length: Specifies a max length for the reverse-path and forward-path field in the SMTP client command. The value range is 16 to 512 bytes (including punctuation marks).

Max reply line length: Specifies a max reply line length for the SMTP server. The value range is 64 to 1024 bytes (including carriage return).

Max text line length: Specifies a max length for the E-mail text of the SMTP client. The value range is 64 to 2048 bytes (including carriage return).

Max content type length: Specifies a max length for the Content-Type field. The value range is 64 to 1024 bytes

Max content filename length: Specifies a max length for the filename of E-mail attachment. The value range is 64 to 1024 bytes

Max failure time: Specifies a max failure time (within one single SMTP session) for the SMTP server. The value range is 0 to 512 times.


Telnet

Action for brute-force: If the login attempts per minute fail for the times specified by the threshold, system will identify the attempts as an intrusion and take an action according to the configuration.

Protocol anomaly detection: Specifies a check level for the protocol validity check of the signature set.

Username/Password max length: Specifies a max length for the username and password used in Telnet. The value range is 64 to 1024 bytes


Other-TCP/Other-UDP/IMAP/Finger/NNTP/TFTP/SNMP/MySQL/MSSQL/ORACLE/NetBIOS/DHCP/LDAP/VoIP

Max scan length: Specifies a max scan length. The value range is 0 to 65535 bytes.


SUNRPC

Protocol anomaly detection: Specifies a check level for the protocol validity check of the signature set.


MSRPC

Action for brute-force: If the login attempts per minute fail for the times specified by the threshold, system will identify the attempts as an intrusion and take an action according to the configuration.

Protocol anomaly detection: Specifies a check level for the protocol validity check of the signature set.

Max bind length: Specifies a max length for MSRPC's binding packets. The value range is 16 to 65535 bytes.

Max request length: Specifies a max length for MSRPC's request packets. The value range is 16 to 65535 bytes.