H3C SecPath Security Products FAQ(V7)-6W100

HomeSupportQuick StartsFAQH3C SecPath Security Products FAQ(V7)-6W100

27-WAF FAQ

WAF FAQ

Q.     What’s difference between WAF and IPS?

WAF defends against Web attacks and also protects the device against other abnormal operations including frequent logins. In summary, WAF and IPS functions overlap with each other but also have distinct differences. If both IPS and WAF policies are applied, some attacks might match both.

Q.     Why a WAF policy does not match any packets after I apply it to a DPI application profile and use the DPI application profile in a security policy rule or object policy rule?

Possible reasons are as follows:

·     The device might not be installed with a license as required. The WAF module requires a license to run on the device.

·     The packet matching rules in WAF policies might have not been deployed to the detection engine kernel of the application layer. When the device receives attack packets but no packet matching rules exist, these attack packets cannot be matched.

Q.     Why no threat logs are generated when WAF policies are applied and the device are attacked?

At present, WAF does not support viewing the corresponding log messages from the Web interface.

To view WAF log messages:

1.     On the System > Log Settings > WAF Log page, select Output WAF logs through fast log output.

2.     On the System > Log Settings > Basic Settings > Fast Log Output page, configure log hosts and select WAF logs. Then, you can view WAF log messages on the log hosts.

Q.     What the device will do if an attack matches both WAF policy and IPS policy?

If an attack packet matches both WAF policy and IPS policy, log messages are generated on both matches. The device will take the action of the highest priority among the actions for the WAF policy and IPS policy. The actions in descending order of priority are drop > reset > redirect > permit.

 

不同款型规格的资料略有差异, 详细信息请向具体销售和400咨询。 H3C保留在没有任何通知或提示的情况下对资料内容进行修改的权利!
  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
All Support
  • Become A Partner
  • Partner Policy & Program
  • Global Learning
  • Partner Sales Resources
  • Partner Business Management
  • Service Business
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网