CFW can defend against network attacks and virus files. You are advised to set Protection Mode to Intercept in a timely manner.
Function |
Description |
Check Type |
Configuration Method |
|---|---|---|---|
Basic defense |
A built-in rule library. It covers common network attacks and provides basic protection capabilities for your assets. |
|
For details about how to view and modify rule library settings, see Modifying the Protection Action of an Intrusion Prevention Rule. |
Virtual patch |
Hot patches are provided for IPS at the network layer to intercept high-risk remote attacks in real time and prevent service interruption during vulnerability fixing. Updated rules are added to the virtual patch library first. You can determine whether to add the rules to the basic defense library. To add defense rules, enable this function to apply virtual patch rules. The protection action can be manually modified. |
||
Custom IPS signature (supported only by the professional edition) |
If the built-in rule library cannot meet your requirements, you can customize signature rules. |
The check types are the same as those of Basic defense. Signature rules of the HTTP, TCP, UDP, POP3, SMTP and FTP protocols can be added. |
For details, see Customizing IPS Signatures. |
For details about antivirus, see Blocking Virus-infected Files.
For details about the protection overview, see Viewing Attack Defense Information on the Dashboard. For details about logs, see Attack Event Logs.