SOPHOS ET80 - INTRUSION PREVENTION ON
SOPHOS FIREWALL
What are the three parts of Sophos Intrusion Prevention? - Answers- IPS Policies,
Spoof protection and DoS protection
What are IPS policies used for? - Answers- They are applied to firewall rules and used
to protect against exploits and malformed traffic
What is spoof protection used for? - Answers- Drops traffic that pretends its from a
different MAC or IP address to bypass protection
What is denial-of-service protection used for? - Answers- Drops traffic that is
maliciously trying to prevent genuine traffic trying to access services
How do IPS polices work? - Answers- By using a collection of rules to detect malicious
and malformed data
What do you have to do in the Sophos firewall before you can configure IPS rules? -
Answers- You have to enable IPS protection
Where can you enable IPS protection on a Sophos Firewall? - Answers- Protect >
Intrusion prevention > IPS policies > IPS protection > On
What happens to the IPS signatures after disabling IPS on the firewall? - Answers- The
signatures will be deleted after 30 days
What does the smart filter do in the configuration of an IPS policy rule? - Answers- It
allows for the automatic additions of new patterns that match the selected criteria.
What IPS signature library Does Sophos use as part of its IPS protection? - Answers-
Talos commercial IPS signature library from Cisco
What happens if you use the selected individual signatures only option as part of an IPS
rule configuration? - Answers- It will only use the Selected signatures, and won't
automatically update and use up to date ones
What does an IPS policy need to have to work? - Answers- It needs to be applied to a
firewall rule to be active. The firewall rule will determine what traffic is checks and the
IPS policy will determine what checks are carried out
What are the 3 additional DoS & spoof protection services called? - Answers- IP
spoofing, MAC filter and IP-MAC filter
SOPHOS FIREWALL
What are the three parts of Sophos Intrusion Prevention? - Answers- IPS Policies,
Spoof protection and DoS protection
What are IPS policies used for? - Answers- They are applied to firewall rules and used
to protect against exploits and malformed traffic
What is spoof protection used for? - Answers- Drops traffic that pretends its from a
different MAC or IP address to bypass protection
What is denial-of-service protection used for? - Answers- Drops traffic that is
maliciously trying to prevent genuine traffic trying to access services
How do IPS polices work? - Answers- By using a collection of rules to detect malicious
and malformed data
What do you have to do in the Sophos firewall before you can configure IPS rules? -
Answers- You have to enable IPS protection
Where can you enable IPS protection on a Sophos Firewall? - Answers- Protect >
Intrusion prevention > IPS policies > IPS protection > On
What happens to the IPS signatures after disabling IPS on the firewall? - Answers- The
signatures will be deleted after 30 days
What does the smart filter do in the configuration of an IPS policy rule? - Answers- It
allows for the automatic additions of new patterns that match the selected criteria.
What IPS signature library Does Sophos use as part of its IPS protection? - Answers-
Talos commercial IPS signature library from Cisco
What happens if you use the selected individual signatures only option as part of an IPS
rule configuration? - Answers- It will only use the Selected signatures, and won't
automatically update and use up to date ones
What does an IPS policy need to have to work? - Answers- It needs to be applied to a
firewall rule to be active. The firewall rule will determine what traffic is checks and the
IPS policy will determine what checks are carried out
What are the 3 additional DoS & spoof protection services called? - Answers- IP
spoofing, MAC filter and IP-MAC filter