EasyManua.ls Logo

HP ProCurve 6200yl Series User Manual

HP ProCurve 6200yl Series
390 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #60 background imageLoading...
Page #60 background image
Virus Throttling
Introduction
deployed to hosts, the network remains functional and the overall
distribution of the malicious code is limited.
Connection-Rate filtering is a countermeasure tool you can use in your inci-
dent-management program to help detect an manage worm-type IT security
threats received in inbound routed traffic. Major benefits of this tool include:
Behavior-based operation that does not require identifying details
unique to the code exhibiting the worm-like operation.
Handles unknown worms.
Needs no signature updates.
Protects network infrastructure by slowing or stopping routed traffic
from hosts exhibiting high connection-rate behavior.
Allows network and individual switches to continue to operate, even
when under attack.
Provides Event Log and SNMP trap warnings when worm-like
behavior is detected
Gives IT staff more time to react before the threat escalates to a crisis.
Note When configured on a port, connection-rate filtering is triggered by routed
IPv4 traffic received inbound with a relatively high rate of IP connection
attempts. (Connection-Rate filtering is not triggered by such traffic when
both the SA and DA are in the same VLAN—that is, switched traffic). Note
that connection-rate filtering applies only to routed traffic. Switched traffic
from a blocked or throttled host is not blocked or throttled.
5400zl with Routing
Configured
Networked
Servers
Internet
Configuring connection-rate filtering
on the switch protects the devices
on VLANs 1 and 2 from the high
connection-rate traffic
(characteristic of worm attacks) that
is being routed from VLAN 3.
Devices on VLAN 3 Infected
with Worm-Like Malicious Code
A
B
C
D
VLAN 1
VLAN 2
VLAN 3
Figure 3-1. Example of Protecting a Network from Agents Using a High IP Connection Rate To Propagate
3-4

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the HP ProCurve 6200yl Series and is the answer not in the manual?

HP ProCurve 6200yl Series Specifications

General IconGeneral
Rack Unit Size1U
Power DeviceInternal power supply
Operating Humidity10% to 90% non-condensing
Product SeriesProCurve 6200yl
Ports24 - 48 x 10/100/1000
Uplink Ports4 x SFP+ (10GbE) or 4 x 10/100/1000
Power over Ethernet (PoE)Optional, depending on model
ManagementWeb-based, CLI, SNMP
MAC address table size32, 000 entries
Jumbo Frame SupportYes
Routing ProtocolRIP, OSPF, BGP
Remote Management ProtocolSSH
Authentication MethodRADIUS, TACACS+
Compliant StandardsIEEE 802.1D, 802.1Q, 802.1W, 802.1S, 802.3
Power Supply100-240 VAC, 50/60 Hz
Dimensions (W x D x H)440 x 430 x 44 mm
Operating Temperature0 to 45 °C

Related product manuals