Home Theater Server User Manual
Table Of Contents
- Contents
- About This Document
- Network Security
- TCP SYN attacks
- IP TCP syn-proxy
- Granular application of syn-proxy feature
- Syn-def
- No response to non-SYN first packet of a TCP flow
- Prioritizing management traffic
- Peak BP utilization with TRAP
- Transaction Rate Limit (TRL)
- Understanding transaction rate limit
- Configuring transaction rate limit
- Configuring the maximum number of rules
- Saving a TRL configuration
- Transaction rate limit command reference
- Global TRL
- TRL plus security ACL-ID
- security acl-id
- Transaction rate limit hold-down value
- Displaying TRL rules statistics
- Displaying TRL rules in a policy
- Displaying IP address with held down traffic
- Refusing new connections from a specified IP address
- HTTP TRL
- Overview of HTTP TRL
- Configuring HTTP TRL
- Displaying HTTP TRL
- Display all HTTP TRL policies
- Display HTTP TRL policy from index
- Display HTTP TRL policy client
- Display HTTP TRL policy starting from index
- Display HTTP TRL policy matching a regular expression
- Display HTTP TRL policy client index (MP)
- Display HTTP TRL policy client index (BP)
- Display HTTP TRL policy for all client entries (BP)
- Downloading an HTTP TRL policy through TFTP
- HTTP TRL policy commands
- Logging for DoS Attacks
- Maximum connections
- clear statistics dos-attack
- Maximum concurrent connection limit per client
- Firewall load balancing enhancements
- Syn-cookie threshhold trap
- Service port attack protection in hardware
- Traffic segmentation
- DNS attack protection
- Access Control List
- How ServerIron processes ACLs
- Default ACL action
- Types of IP ACLs
- ACL IDs and entries
- ACL entries and the Layer 4 CAM
- Configuring numbered and named ACLs
- Modifying ACLs
- Displaying a list of ACL entries
- Applying an ACLs to interfaces
- ACL logging
- Dropping all fragments that exactly match a flow-based ACL
- Enabling ACL filtering of fragmented packets
- Enabling hardware filtering for packets denied by flow-based ACLs
- Enabling strict TCP or UDP mode for flow-based ACLs
- ACLs and ICMP
- Using ACLs and NAT on the same interface (flow-based ACLs)
- Displaying ACL bindings
- Troubleshooting rule-based ACLs
- IPv6 Access Control Lists
- Network Address Translation
- Syn-Proxy and DoS Protection
- Understanding Syn-Proxy
- Configuring Syn-Proxy
- DDoS protection
- Configuring a security filter
- Configuring a Generic Rule
- Configuring a rule for common attack types
- Configuring a rule for ip-option attack types
- Configuring a rule for icmp-type options
- Configuring a rule for IPv6 ICMP types
- Configuring a rule for IPv6 ext header types
- Binding the filter to an interface
- Clearing DOS attack statistics
- Clearing all DDOS Filter & Attack Counters
- Logging for DoS attacks
- Displaying security filter statistics
- Address-sweep and port-scan logging
- Secure Socket Layer (SSL) Acceleration
- SSL overview
- SSL acceleration on the ServerIron ADX
- Configuring SSL on a ServerIron ADX
- Basic SSL profile configuration
- Advanced SSL profile configuration
- Configuring Real and Virtual Servers for SSL Termination and Proxy Mode
- Configuration Examples for SSL Termination and Proxy Modes
- SSL debug and troubleshooting commands
- Displaying socket information

ServerIron ADX Security Guide 145
53-1002440-03
Configuring SSL on a ServerIron ADX
6
11. When prompted for the import password, enter the password you used when exporting the
certificate to a PFX file. You should receive a message that says MAC verified OK. The resulting
file contents will resemble the following:
1.3.6.1.4.1.311.17.2: <No Values>
localKeyID: 01 00 00 00
Microsoft CSP Name: Microsoft RSA SChannel Cryptographic Provider
friendlyName: 740b399c4eb957ca6b972da9345dbda3_e7adefb8-6420-4ed2-
b6f5-2c4988094b69
Key Attributes
X509v3 Key Usage: 10
-----BEGIN RSA PRIVATE KEY-----
MIICWwIBAAKBgQCrSx5QmEBB35QZqKZLzt9uC9ZPmL8sNI/yNfDlh0BnT3Y0xcxV
Uo+buHIwGNcFKQgTQJRvZ1UlvLfKzETT9VWlUv6PsWLonxUZEWFion+ThOo5zQYe
/i/EZe5APF0CKdBAVlBONs2FOsxztTA2zrBzpxtlc7NyjJWLmYdjqyQujwIDAQAB
AoGAbugfQ62ghUY+vPJOYe0bC0SMyVKsDPIndXrpc6PD1mBDt92N9HyVUQz2mh+r
MMMlYFnDAfKU1e8/zQW/VsGVZnuIVgc5kk43BGo69o5Tvvw/7w+Vr8X95fXie72i
noWPvaOsONoV72oBKsKCfxgmEwurGWT/MoL6KG0Uw65bCLECQQDUYYg5R7cS9pKi
bX8yVv71l5gazYbo34YqDXniQlY2PtxTKjkg4cJ1WxbJeSRAj7N+kteKsp0emBJ8
OyeOt+UJAkEAznlN3YYn+WTM2whGfivj/B+EkMaB0sJJNAnWg4Zd1aR40uQsnNVE
Qj6svvFAYNY9zEZ5XG4Kbcl4zilH4wU01wJAHCNr9ALfa6DFnsWZI6dJEmrqWSq/
5ByxXuL4MhUN7RP5Bv/CH+wpYnkWFM17Ex627l8wNY0iqgoF8PW5cPxGWQJAIswU
0GG8uO5BDCT/5GG3QZV6PQAHfyKZPbjuuynZBJl8d2ZXEnNq1pNDf8ae5/MTZSr3
ZxlwjoIm5u/UGrGU7wJAR4lxl9/qhu+db0aBjBIEOfs/9NuRh5RMDEZF+ZXdKcE9
inV5o51vyVLMXZfknishbKWOBS62POMXJsOt+w9I0g==
-----END RSA PRIVATE KEY-----
Bag Attributes
localKeyID: 01 00 00 00
friendlyName: www.brocade.com
subject=/C=US/ST=Texas/L=Dallas/O=Brocade/OU=Engineering/CN=www.brocade.com
issuer=/DC=com/DC=brocade/O=Brocade/OU=Engineering/CN=www
-----BEGIN CERTIFICATE-----
MIICxTCCAi6gAwIBAgIQDmM2IYR4YnLzCLr31Z/DPzANBgkqhkiG9w0BAQUFADBm
MRMwEQYKCZImiZPyLGQBGRYDb3JnMRgwFgYKCZImiZPyLGQBGRYIam9uZGF2aXMx
EDAOBgNVBAoTB1Rla2VsZWMxETAPBgNVBAsTCFNlY3VyaXR5MRAwDgYDVQQDEwdU
ZWtlbGVjMB4XDTA1MDQxOTAxNTY0OFoXDTA3MDgwNDE3NDQ0OFowczELMAkGA1UE
BhMCVVMxDjAMBgNVBAgTBVRleGFzMQ8wDQYDVQQHEwZEYWxsYXMxEDAOBgNVBAoT
B1Rla2VsZWMxETAPBgNVBAsTCFNlY3VyaXR5MR4wHAYDVQQDExVhaXJlc3BhY2Uu
dGVrZWxlYy5jb20wgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAKtLHlCYQEHf
lBmopkvO324L1k+Yvyw0j/I18OWHQGdPdjTFzFVSj5u4cjAY1wUpCBNAlG9nVSW8
t8rMRNP1VaVS/o+xYuifFRkRYWKif5OE6jnNBh7+L8Rl7kA8XQIp0EBWUE42zYU6
zHO1MDbOsHOnG2Vzs3KMlYuZh2OrJC6PAgMBAAGjZzBlMBMGA1UdJQQMMAoGCCsG
AQUFBwMBMA4GA1UdDwEB/wQEAwIDODAfBgNVHSMEGDAWgBRW7ldC6sXhjQlDL+Sv
jLh4fOG5wTAdBgNVHQ4EFgQUG1P0iW0rJX1rUYtlEFmzayzxHkEwDQYJKoZIhvcN
AQEFBQADgYEAgI7MP/4PSiyDm/vZzE4Rmxlhrju+6xN9Q2PVVpOY3P/WE3QOtkOw
4nShKlLucDaC0m+sJjKzVi5Ezv7ebWSKq5rF+3NvgOIouh2vqCI1AgyI7QCkxTWW
PoYSssBzh+b+IK6+XsbekTfH3ghcM1+Yx+RZP9eIGSFRT/oTZnC87D0=
-----END CERTIFICATE-----










