- Table of Contents
- Related Documents
-
Title | Size | Download |
---|---|---|
12-Security action | 21.76 KB |
Security action
Introduction
The security action module can provide action parameters for DPI service modules such as IPS and antivirus. The following action parameter profiles are available:
· Block—Defines the block period for the block source action in DPI service modules. The block source action takes effect only after the blacklist feature is enabled. With the blacklist feature enabled, the device drops a matching packet and adds the packet's source IP address to the IP blacklist. Subsequent packets from the source IP address will be dropped directly during the block period.
For more information about the blacklist feature, see attack defense online help.
· Redirect—Defines the URL to which packets are redirected for the redirect action in DPI service modules.
· Capture—Defines parameters for the capture action in DPI service modules, such as maximum number of bytes that can be cached and URL to which cached packets are exported.
The device caches captured packets locally and exports the cached packets to the designated URL at the daily export time or when the number of cached bytes reaches the limit. After the export, the device clears the local cache and starts to capture new packets. If you do not specify a URL or the specified URL is not reachable, the device still exports the cached captured packets but the export will fail and the local cache will be cleared.
· Alarm—Defines the anti-virus alarm message to be displayed on the client. Click Create to create an alarm message template, click Edit at the right side of the template, and then import the required alarm message. In one alarm message template, you can define an alarm message by importing a TXT or HTML file.