Sophos XGÄ~©Ó¦ÛCyberoam¦³´£¨Ñ²³æªºDoS¨¾Å@³]©w¡C
³o²³æªºDoS¨¾Å@¤À¬°SYN/UDP/TCP/ICMP¥|¤jÃþªºflood»Öȳ]©w¡A
¥un¶W¥X³]©wÈ¡A¦h¾lªº«Ê¥]´N·|³Q¥á±ó¡C
¦Ó³Q¥á±óªº«Ê¥]¼Æ¶q«h·|¥X²{¦b²Ä¤@Ó¶±ªºDoS Attacks²Îpªí¤¤¡C
¤£¹L³oÓWebUIªºDoS¨¾Å@¨ä¹ê¬Û·í¶§¬K¡A«h¤F¿ï¾Ü¨Ó·½ºÝ©Î¥ØªººÝªº±Ò¥Î»P§_»P»ÖÈ¥~¡A
µLªk°µ¨ì¨ä¥¦½Ñ¦p¬YÓ¤¶±©ÎZone¨ì¥t¤@Ӱϰ쪺²Ó¶µ³]©w¡C
¦b¤W¤FSophos XGªºArchitect½Òµ{«á¡Aµo²{ì¨ÓDoS¥\¯à¦³¨ä¥¦¶i¶¥²Ó¶µ³]©w¡A
¥u¤£¹L³o¨Ç²Ó¶µ³]©w¥²»Ý¦bConsole Mode¤U³z¹L«ü¥O¨Ó¤U¹F¡C
Sophos XG DoSªº¶i¶¥³]©w¥]§t¨âÓ¥Dn¦¨ûDoS Policy»PDoS Rule¡C
´N¦p¦P¨ä¥¦¨¾¤õÀð³W«h¤@¼Ë¡A¥ý¦bDoS Policy©w¸q¦nn¹LÂoªºProtocol»P»ÖÈ¡A
µM«á¦bDoS Rule¤¤©w¸q¦nn®M¥ÎªºDoS Policy»P¨Ó·½/¥Øªº°Ï°ì¡A³o¼Ë´N§¹¦¨¤F¡ã
DoS Policy«ü¥O¦p¤U¡C
System dos-config add dos-policy policy-name <name> [SYN-Flood <limit> pps <per-src|per-dst|global>] [UDP-Flood <limit> pps <per-src|per-dst|global>] [ICMP-Flood <limit> pps <per-src|per-dst|global>] [IP-Flood <limit> pps <per-src|per-dst|global>]
Dos Rule«ü¥O¦p¤U¡C
system dos-config add dos-rule rule-name <name> [options] [rule-position <position>] dos-policy <policy-name>
Á|¨Ò¨Ó»¡¡AY§ÚÌ·Q³]©w¨C¬í¤£¯à¶W¹L100ÓUDP«Ê¥]ªºDoS Policy¡A
µM«á®M¥Î¦bLAN to DMZªº¤è¦V¤W¡A¹ï¨CÓ¨Ó·½ºÝ°µ¨î¡A
¨ä«ü¥O¦p¤U¡C(DMZºô¬q¬°10.1.1.0/24)
system dos-config add dos-policy policy-name UDP-Test UDP-Flood 100 pps per-src
system dos-config add dos-rule rule-name LAN-to-DMZ-UDP src-zone LAN dstip 10.1.1.0 netmask 255.255.255.0 protocol udp dos-policy UDP-Test
·í®M¥Î§¹³]©w¡A±qLANºÝ¥´¥X¤j¶qUDP«Ê¥]¨ìDMZºÝ®É¡A¤j©ó100 ppsªº«Ê¥]´N·|³QXGµ¹Äd¤U¡A¦ÓÅã¥Ü¦bDoS Attacks²Îp¶±¤¤¡C
°Ñ¦Ò¸ê®Æ
¶¶¤l¥Î¨Ó¥´¤j¶q«Ê¥]ªº¤u¨ã¬OLOIC¡A¥i¦b ³oùØ ¤U¸ü¡C
♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã
If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!
|