Secure Computing SG570 Manual de usuario Pagina 183

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 341
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 182
The top level page has a checkbox Block Unscanned Hosts which defines the behavior
for a host which hasn't been scanned or is not defined to be scanned.
The Simultaneous Probes setting specifies the maximum number of different hosts that
should be scanned together.
The Minimum Inter Probe Delay specifies a minimum number of seconds between
scans of a single host. It also specifies the maximum time for changes to take effect.
In addition to enforcing the services aspect of security groups, it is possible to include a
number of NASL (Nessus Attack Scripting Language) scripts in /etc/config on the unit and
to define some or all of these to be run against the target hosts. Typically, one would use
attack scripts from the Nessus suite to scan for specific vulnerabilities and exploits on a
host. If any script detects such vulnerability, Internet access is again blocked. The list of
available scripts is automatically populated from the files ending with .nasl in /etc/config.
Security groups may overlap with respect to hosts within them. In this case, a single
allow service overrides any number of denies of that same service. However, NASL
scripts and overlapping groups do not interoperate particularly well and should be
avoided.
177
Firewall
Vista de pagina 182
1 2 ... 178 179 180 181 182 183 184 185 186 187 188 ... 340 341

Comentarios a estos manuales

Sin comentarios