Configuring Basic IPS Protection
Scenario
In routine network security management, enterprises face various threats from the Internet, such as DDoS attacks and SQL injection. The built-in rule library of CFW covers common network attacks and provides basic protection capabilities for your assets. You can change the protection mode to adjust the protection status of the rule library, achieving more flexible and secure network protection.
This section describes how to configure basic IPS protection.
Notes and Constraints
- Intrusion prevention does not support decryption detection and defense for TLS- and SSL-encrypted traffic.
- If custom IPS rules have been added, IPS basic protection cannot be disabled.
- If IPS basic protection is disabled, the virtual patch, sensitive directory scan prevention, and reverse shell detection prevention functions will be disabled with it.
Impacts on Services
If IPS blocking is enabled, a range of possible threats and suspicious traffic will be blocked. To change the protection mode, you are advised to enable the Observe mode and check false alarms for a period of time and then switch to the Intercept mode.
Intrusion Prevention System (IPS)
IPS detects and defends against access traffic in real time based on the attack defense experience and rules accumulated over the years, blocking common network attacks and effectively protecting your assets.
- Basic protection: A built-in rule library. It covers common network attacks and provides basic protection capabilities for your assets. You can change the protection mode to change the protection status of the rule library. For details, see Adjusting the IPS Protection Mode to Block Network Attacks. For details about how to change the protection status of a single rule, see Changing the Protection Action of an Intrusion Prevention Rule.
- Virtual patching: Hot patches are provided for IPS at the network layer to intercept high-risk remote attacks in real time and prevent service interruption during vulnerability fixing.
Updated rules are added to the virtual patch library first. You can determine whether to add the rules to the basic protection library.
To add defense rules, enable this function to apply virtual patch rules. The protection action can be manually modified.
- Custom IPS signature (supported only by the professional edition): If the built-in rule library cannot meet your requirements, you can customize signature rules. For details, see Adding a Custom IPS Signature.
Signature rules of the HTTP, TCP, UDP, POP3, SMTP and FTP protocols can be added.
Adjusting the IPS Protection Mode to Block Network Attacks
- Enable at least one type of traffic protection.
- For details about how to enable EIP traffic protection, see Enabling Internet Border Traffic Protection.
- For details about how to enable VPC traffic protection, see Enabling VPC Border Traffic Protection.
- For details about how to enable traffic protection for private IP addresses, see Enabling NAT Gateway Traffic Protection.
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane on the left, choose .
- Ensure Basic Protection is enabled.
- In the Protection Mode area, select a protection mode.
Table 1 Protection mode Protection Mode
Description
Observe
Attacks are detected and recorded in logs but are not blocked.
Intercept
Attacks and abnormal IP address access are automatically blocked.
- Intercept mode - loose: The protection granularity is coarse. In this mode, only attacks with high threat and high certainty are blocked.
- Intercept mode - moderate: The protection granularity is medium. This mode meets protection requirements in most scenarios.
- Intercept mode - strict: The protection granularity is fine-grained, and all attack requests are intercepted.
NOTE:- You are advised to enable the Observe mode for a period of time and then switch to the Intercept mode. For details about how to view attack event logs, see Viewing Attack Event Logs.
- If traffic is blocked by mistake, you can modify the action of a rule in the basic defense rule library. For details, see IPS Rule Management.
The Intercept status of a rule varies depending on the protection mode. For details, see Table 2. For details about how to modify an IPS rule, see Changing the Protection Action of an Intrusion Prevention Rule.
Table 2 Default actions of rule groups in different protection modes -
Observe
Intercept mode - strict
Intercept mode - medium
Intercept mode - loose
Observe rule group
Observe
Disable
Disable
Disable
Strict rule group
Observe
Intercept
Disable
Disable
Medium rule group
Observe
Intercept
Intercept
Disable
Loose rule group
Observe
Intercept
Intercept
Intercept
- In the displayed dialog box, click OK.
Disabling IPS Basic Protection
- If custom IPS rules have been added, IPS basic protection cannot be disabled.
- If IPS basic protection is disabled, the virtual patch, sensitive directory scan prevention, and reverse shell detection prevention functions will be disabled with it.
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane on the left, choose .
- Click the toggle button next to Basic Protection and click OK in the dialog box that is displayed.
Follow-up Operations
For details about the protection overview, see Event Center. For details about logs, see Viewing Attack Event Logs.
References
For details about how to handle incorrect IPS blocking, see What Do I Do If IPS Blocks Normal Services?
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot