Summary of the content on the page No. 1
ZyWALL IDP 10
Intrusion Detection Prevention Appliance
Support Notes
Version 1.0
Aug 2004
Summary of the content on the page No. 2
IDP Support Notes INDEX Application Notes............................................................................................................................ 4 Deploy IDP ................................................................................................................................4 Register ZyWALL IDP ............................................................................................................10 Firmware Upgrade ..............................
Summary of the content on the page No. 3
IDP Support Notes Why can’t I input mail server address by domain name?........................................................32 What’s “Drop” and “Block Connection” for Action of User Defined Policy?........................33 How to use URL String in Content setup of User-defined policy?..........................................33 What’s the definition of “Incoming” and “Outgoing” direction in a policy setup?.................33 How to decide which Interface should be applied for pol
Summary of the content on the page No. 4
IDP Support Notes Application Notes Deploy IDP IDP functions as a plug and play bridge device filtering malicious traffic from attacking your networks. With continuous signatures update, users can get free from network-based intrusions. In this example, we describe how to deploy and configure ZyWALL IDP10 in a network. Since ZyWALL IDP10 is a bridge device, users don’t need to change the existing network topology when they deploy it. Two things matter are Determine the target ne
Summary of the content on the page No. 5
IDP Support Notes Servers/PC 192.168.2.5-10 LAN1: 192.168.1.5-50 LAN2: 192.168.1.51-100 WLAN: 192.168.1.101-130 Data Center: 192.168.1.131-140 Device IDP (A) IDP (B) IDP (C) IP Address 192.168.1.141 192.168.1.142 192.168.1.143 Device IDP (D) IDP (E) IDP (F) IP Address 192.168.1.144 192.168.1.145 192.168.1.146 Purpose: IDP (A) Since network devices may also have vulnerabilities, once the firewall device at gateway is compromised, the protected networks are also endangered. Th
Summary of the content on the page No. 6
IDP Support Notes Setup IP address of IDP (A, B, C, D, E, F) 1. Configure each IDP device’s IP address. Since IDP is a bridge device, it only has one IP address for management purpose, IDP also uses this IP address to update signatures and the send system logs through syslog/E-mail/FTP. To configure the system IP address of IDP device, users can choose two methods, - Through Console 1. Make sure the baud rate/data/parity/stop/flow control settings are as below. 2. Default Log
Summary of the content on the page No. 7
IDP Support Notes 1. Connect one PC to IDP’s management port by crossed Ethernet cable. Make sure MGMT port light is on. 2. Go to Start->Settings->Network and Dial-up Connections, and select the Ethernet connection you are connecting to IDP device. 3. Change PC’s IP address to 192.168.1.5, subnet mask= 255.255.255.0 from properties. 4. Log into IDP’s WEB GUI via browser. 7 All contents copyright (c) 2004 ZyXEL Communications Corporation.
Summary of the content on the page No. 8
IDP Support Notes 5. Go to SYSTEM->General->Device, input IDP (A,)’s IP address, subnet mask, default gateway, DNS server’s IP address. 6. Repeat step 1-5 to configure IDP (B, C, D, E, F) according to IP address assignment table. 8 All contents copyright (c) 2004 ZyXEL Communications Corporation.
Summary of the content on the page No. 9
IDP Support Notes Connect the MGMT/LAN/WAN ports of all IDP devices to the network according to the deployment topology (192.168.1.0/24). Login IDP (A, E)’s WEB GUI; go to SYSTEM->INTERFACE->Policy Check. Then enable policy checking on WAN port of IDP (A, E). Login IDP (B, C, D)’s WEB GUI, go to SYSTEM->INTERFACE->Policy Check. Then enable policy checking on WAN and LAN port of IDP (A). Login IDP (F)’s WEB GUI; go to SYSTEM->INTERFACE->Policy Check. Then enable poli
Summary of the content on the page No. 10
IDP Support Notes Register ZyWALL IDP ZyWALL IDP comes with a “pre-defined” policy set which requires subscription and can be update at regular bases. Having an up-to-date policy set is essential as new attack types evolve. 1. A “Device License Key” card is included in ZyWALL IDP package for one year free subscription. 10 All contents copyright (c) 2004 ZyXEL Communications Corporation.
Summary of the content on the page No. 11
IDP Support Notes 2. Go to ZyXEL Communications online services center. http://www.myZyXEL.com. 3. In case you haven't got an account on myZyXEL.com, you need to get a new account. Please follow the instruction on myZyXEL.com; we skip the description of detailed procedure in this article. If you get into trouble in this step, please contact ZyXEL support. 4. Login into myZyXEL.com using your account. “Click here” to register ZyWALL IDP. 11 All contents copyright (c) 2004 ZyX
Summary of the content on the page No. 12
IDP Support Notes 5. Press add button to add the ZyWALL IDP you have. 6. In this step you need to enter Serial Number, Authentication Code (MAC address), and a Friendly Name for your product. You can find serial number and MAC address at the bottom of your device. 12 All contents copyright (c) 2004 ZyXEL Communications Corporation.
Summary of the content on the page No. 13
IDP Support Notes 7. Input the date you purchase the product, and the purpose of the buying. 8. You would get a successful message. Then press Continue button. 13 All contents copyright (c) 2004 ZyXEL Communications Corporation.
Summary of the content on the page No. 14
IDP Support Notes 9. From ZyWALL IDP’s Applicable Service List, you will have a service "IDP Signature Update" available. Click Activate. 10. Enter the license key you get from “Device License Key” card. Then press Submit button. 14 All contents copyright (c) 2004 ZyXEL Communications Corporation.
Summary of the content on the page No. 15
IDP Support Notes 11. After clicking Submit button, you will get an “Activation Key” and “Service Set Key”. An email with these keys will be send to your email address as well. 12. You can copy & paste “Activation Key” to ZyWALL IDP’s Registration page. 15 All contents copyright (c) 2004 ZyXEL Communications Corporation.
Summary of the content on the page No. 16
IDP Support Notes Firmware Upgrade 1. Under Maintenance you can find F/W Upload tab. Click browse to select firmware file (.bin) and click Upload button to start firmware upload. 2. It may take few minutes for firmware upload process to finish. ZyWALL IDP will reboot when firmware upload completed. 16 All contents copyright (c) 2004 ZyXEL Communications Corporation.
Summary of the content on the page No. 17
IDP Support Notes Signature Update *Make sure you have registered your ZyWALL IDP before you do the signature update. To update pre-defined policy for your ZyWALL IDP, login into ZyWALL IDP via HTTP, go to IDP > Update and enter Update Server’s domain name (updateidp.zyxel.com) 1. You could click Update Now to force ZyWALL IDP to perform signature update immediately. 2. Enable “Auto Download & Update” if you want to perform update during non-peak hour. 17 All contents cop
Summary of the content on the page No. 18
IDP Support Notes Configure User Defined Policy In this example, we describe the procedure of using user defined policy. We take eMule application as an example. eMule is a P2P file sharing application. In the following description we break down the procedure of how to get and analysis eMule traffic pattern, and how to setup user defined policy in IDP. 1. Get Ethereal installed on a PC. Ethereal is a freeware packet capturing tool, you can get a freed download from http://ww
Summary of the content on the page No. 19
IDP Support Notes 4. Start ethereal packet capturing. 5. Initiate eMule connection from the internal PC, be sure to reduce unnecessary traffic if possible. 6. Stop packet capturing. 7. Analyze the packet. In ethereal, you will get 3 sub-windows. The first window displays summary of each packet in time sequence. In the second window, you can check the parsed details of the selected packet. In the third window, the selected packet is displayed in Hexadecimal and ASCII format respe
Summary of the content on the page No. 20
IDP Support Notes 8. Count the TCP offset and the length of “http://emule-prjoect.net” 9. Create User-defined policy in IDP. Login to IDP’s WEB GUI; go to IDP->User-defined. We’ll create a user-defined policy for TCP protocol, with offset=38 bytes, matching depth=24 bytes. Please note that the starting point of offset depends on which protocol you select. For TCP (UDP/ICMP) protocol, the offset starts from the starting points of TCP (UDP/ICMP) payload. IP and TCP (UDP/ICMP) heade