Example 1 – PLANET CS-2000 User Manual
Page 457

CS-2000 UTM Content Security Gateway User’s Manual
- 451 -
Example 1
The CS-2000 can make the alert and also prevent the DDoS attack packets from the internal
virus-infected PCs.
Step1.
In Anomaly IP Æ Setting :
The threshold sessions of virus-infected is ( default is 100 sessions/sec)
Select
Enable Virus-infected IP Blocking ( Blocking Time 600 seconds)
Select
Enable E-Mail alert notification.
Select
Enable Snmp Trap Alert Notification.
Select
Enable NetBIOS Alert Notification.
Enter 192.168.189.30 in IP Address of Administrator.
Click OK.
The anomaly flow IP setting
Enable Co-Defense System, then the CS-2000 can send the defense message to the assigned Switch
Model. And the switch will block the anomaly flow packets which sent to this switch model.
User can add Non-detect IP, and system will not detect the flow of Non-detect IP.