EasyManuals Logo

HP ProCurve 5406zl Access Security Guide

HP ProCurve 5406zl
390 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #60 background imageLoading...
Page #60 background image
Virus Throttling
Introduction
deployed to hosts, the network remains functional and the overall
distribution of the malicious code is limited.
Connection-Rate filtering is a countermeasure tool you can use in your inci-
dent-management program to help detect an manage worm-type IT security
threats received in inbound routed traffic. Major benefits of this tool include:
Behavior-based operation that does not require identifying details
unique to the code exhibiting the worm-like operation.
Handles unknown worms.
Needs no signature updates.
Protects network infrastructure by slowing or stopping routed traffic
from hosts exhibiting high connection-rate behavior.
Allows network and individual switches to continue to operate, even
when under attack.
Provides Event Log and SNMP trap warnings when worm-like
behavior is detected
Gives IT staff more time to react before the threat escalates to a crisis.
Note When configured on a port, connection-rate filtering is triggered by routed
IPv4 traffic received inbound with a relatively high rate of IP connection
attempts. (Connection-Rate filtering is not triggered by such traffic when
both the SA and DA are in the same VLAN—that is, switched traffic). Note
that connection-rate filtering applies only to routed traffic. Switched traffic
from a blocked or throttled host is not blocked or throttled.
5400zl with Routing
Configured
Networked
Servers
Internet
Configuring connection-rate filtering
on the switch protects the devices
on VLANs 1 and 2 from the high
connection-rate traffic
(characteristic of worm attacks) that
is being routed from VLAN 3.
Devices on VLAN 3 Infected
with Worm-Like Malicious Code
A
B
C
D
VLAN 1
VLAN 2
VLAN 3
Figure 3-1. Example of Protecting a Network from Agents Using a High IP Connection Rate To Propagate
3-4

Table of Contents

Other manuals for HP ProCurve 5406zl

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HP ProCurve 5406zl and is the answer not in the manual?

HP ProCurve 5406zl Specifications

General IconGeneral
Product NameHP ProCurve 5406zl
CategorySwitch
LayerLayer 3
Operating Temperature32°F to 131°F (0°C to 55°C)
Operating Humidity15% to 95% non-condensing
ManagementSNMP, CLI
Power SupplyRedundant power supplies (optional)
Memory128 MB flash, 512 MB SDRAM

Related product manuals