提交安全策略修改关键字

This commit is contained in:
lyf
2021-02-01 18:52:36 +08:00
parent 2641d2e7f3
commit 47110bd5db
3 changed files with 260 additions and 238 deletions

View File

@@ -56,6 +56,31 @@ SecurityPolicy-Deny-HTTP-MaxCombination-Drop
LogSession 1
Enabled open
Security-Policies-OK
sleep 1
#修改策略,修改策略相当于再进行一遍新增
Comment 修改策略
Security-Source Name SecurityPolicy-Deny-HTTP-MaxCombination
EditButton
Initialize-Policie Deny
#新建策略
SecurityPolicy.Create-name SecurityPolicy-Deny-SSL-MaxCombination-Drop
SecurityPolicy.Create-action deny
SecurityPolicy.Create-Source-Button
SecurityPolicy.Create-Source type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.2 post=1
SecurityPolicy.Create-Destination-Button
SecurityPolicy.Create-Destination type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.3 post=1
${fqdnname} create list zdhfqdn
${filter} create list SNI CN SAN
Create-Application-Button
ApplicationSearch SSL
Create-Filter-judge Application=SSL Filter=${filter} SSLSNIname=${fqdnname} CNname=${fqdnname} SANname=${fqdnname}
Deny-subaction action=deny subaction=RST
LogSession 1
Enabled open
Security-Policies-OK
Security-Source Name SecurityPolicy-Deny-SSL-MaxCombination-Drop
${text} get text xpath=//*[@id="ly-table1-listcontent"]/div/div[3]/table/tbody/tr/td[2]/div/div/p
Should Be Equal As Strings ${text} SecurityPolicy-Deny-SSL-MaxCombination-Drop
SecurityPolicy-Deny-HTTP-MaxCombination-RST
#新建对象fqdn
@@ -351,6 +376,189 @@ SecurityPolicy-Deny-HTTP-Host-Alert204
Security-Policies-OK
SecurityPolicy-Deny-SSL-MaxCombination-Drop
#新建对象fqdn
Comment 新建对象fqdn
CreatePage FQDN single zdhfqdn keywordtext=*www.baidu.com
#新建策略
Comment 新建策略
Menu policys Security Policy
SecurityPolicy.CreateButton
SecurityPolicy.Create-name SecurityPolicy-Deny-SSL-MaxCombination-Drop
SecurityPolicy.Create-action deny
SecurityPolicy.Create-Source-Button
SecurityPolicy.Create-Source type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
#SecurityPolicy.Create-Destination-Button
#SecurityPolicy.Create-Destination type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
${fqdnname} create list zdhfqdn
${filter} create list SNI CN SAN
Create-Application-Button
ApplicationSearch SSL
Create-Filter-judge Application=SSL Filter=${filter} SSLSNIname=${fqdnname} CNname=${fqdnname} SANname=${fqdnname}
Deny-subaction action=deny subaction=Drop
LogSession 1
Enabled open
Security-Policies-OK
SecurityPolicy-Deny-SSL-MaxCombination-RST
#新建对象fqdn
Comment 新建对象fqdn
CreatePage FQDN single zdhfqdn keywordtext=*www.baidu.com
#新建策略
Comment 新建策略
Menu policys Security Policy
SecurityPolicy.CreateButton
SecurityPolicy.Create-name SecurityPolicy-Deny-SSL-MaxCombination-Drop
SecurityPolicy.Create-action deny
SecurityPolicy.Create-Source-Button
SecurityPolicy.Create-Source type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
#SecurityPolicy.Create-Destination-Button
#SecurityPolicy.Create-Destination type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
${fqdnname} create list zdhfqdn
${filter} create list SNI CN SAN
Create-Application-Button
ApplicationSearch SSL
Create-Filter-judge Application=SSL Filter=${filter} SSLSNIname=${fqdnname} CNname=${fqdnname} SANname=${fqdnname}
Deny-subaction action=deny subaction=RST
LogSession 1
Enabled open
Security-Policies-OK
SecurityPolicy-Deny-DNS-MaxCombination-Drop
#新建对象fqdn
Comment 新建对象fqdn
CreatePage FQDN single zdhfqdn keywordtext=*www.baidu.com
#新建策略
Comment 新建策略
Menu policys Security Policy
SecurityPolicy.CreateButton
SecurityPolicy.Create-name SecurityPolicy-Deny-SSL-MaxCombination-Drop
SecurityPolicy.Create-action deny
SecurityPolicy.Create-Source-Button
SecurityPolicy.Create-Source type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
#SecurityPolicy.Create-Destination-Button
#SecurityPolicy.Create-Destination type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
${fqdnname} create list zdhfqdn
${filter} create list QNAME
Create-Application-Button
ApplicationSearch DNS
Create-Filter-judge Application=DNS Filter=${filter} QNAMEname=${fqdnname}
Deny-subaction action=deny subaction=Drop
LogSession 1
Enabled open
Security-Policies-OK
SecurityPolicy-Deny-DNS-MaxCombination-Redirect-A
#新建对象fqdn
Comment 新建对象fqdn
CreatePage FQDN single zdhfqdn keywordtext=*www.baidu.com
#新建策略
Comment 新建策略
Menu policys Security Policy
SecurityPolicy.CreateButton
SecurityPolicy.Create-name SecurityPolicy-Deny-SSL-MaxCombination-Drop
SecurityPolicy.Create-action deny
SecurityPolicy.Create-Source-Button
SecurityPolicy.Create-Source type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
#SecurityPolicy.Create-Destination-Button
#SecurityPolicy.Create-Destination type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
${fqdnname} create list zdhfqdn
${filter} create list QNAME
Create-Application-Button
ApplicationSearch DNS
Create-Filter-judge Application=DNS Filter=${filter} QNAMEname=${fqdnname}
Deny-subaction action=deny subaction=Redirect QType=A Avalue=5.5.5.5 Attl=100 CNAMEvalue=www.a.b CNAMEttl=1000
LogSession 1
Enabled open
Security-Policies-OK
SecurityPolicy-Deny-DNS-MaxCombination-Redirect-AAAA
#新建对象fqdn
Comment 新建对象fqdn
CreatePage FQDN single zdhfqdn keywordtext=*www.baidu.com
#新建策略
Comment 新建策略
Menu policys Security Policy
SecurityPolicy.CreateButton
SecurityPolicy.Create-name SecurityPolicy-Deny-SSL-MaxCombination-Drop
SecurityPolicy.Create-action deny
SecurityPolicy.Create-Source-Button
SecurityPolicy.Create-Source type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
#SecurityPolicy.Create-Destination-Button
#SecurityPolicy.Create-Destination type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
${fqdnname} create list zdhfqdn
${filter} create list QNAME
Create-Application-Button
ApplicationSearch DNS
Create-Filter-judge Application=DNS Filter=${filter} QNAMEname=${fqdnname}
Deny-subaction action=deny subaction=Redirect QType=AAAA Avalue=1234::ABCD Attl=100 CNAMEvalue=www.a.b CNAMEttl=1000
LogSession 1
Enabled open
Security-Policies-OK
SecurityPolicy-Deny-FTP-MaxCombination-Drop
#新建对象url
Comment 新建对象url
CreatePage URL single zdhftpurl keywordtext=*.com
#新建Content
Comment Content
CreatePage Key single zdhftpContent keywordtext=*pppp
#新建Account
Comment Account
CreatePage Key single zdhftpAccount keywordtext=*pppp
#新建策略
Comment 新建策略
Menu policys Security Policy
SecurityPolicy.CreateButton
SecurityPolicy.Create-name SecurityPolicy-Deny-SSL-MaxCombination-Drop
SecurityPolicy.Create-action deny
SecurityPolicy.Create-Source-Button
SecurityPolicy.Create-Source type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
#SecurityPolicy.Create-Destination-Button
#SecurityPolicy.Create-Destination type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
${URIname} create list zdhftpurl
${FTPContentname} create list zdhftpContent
${FTPAccountname} create list zdhftpAccount
${filter} create list URI Content Account
Create-Application-Button
ApplicationSearch FTP
Create-Filter-judge Application=FTP Filter=${filter} URIname=${URIname} FTPContentname=${FTPContentname} FTPAccountname=${FTPAccountname}
Deny-subaction action=deny subaction=Drop
LogSession 1
Enabled open
Security-Policies-OK
SecurityPolicy-Deny-FTP-MaxCombination-RST
#新建对象url
Comment 新建对象url
CreatePage URL single zdhftpurl keywordtext=*.com
#新建Content
Comment Content
CreatePage Key single zdhftpContent keywordtext=*pppp
#新建Account
Comment Account
CreatePage Key single zdhftpAccount keywordtext=*pppp
#新建策略
Comment 新建策略
Menu policys Security Policy
SecurityPolicy.CreateButton
SecurityPolicy.Create-name SecurityPolicy-Deny-SSL-MaxCombination-Drop
SecurityPolicy.Create-action deny
SecurityPolicy.Create-Source-Button
SecurityPolicy.Create-Source type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
#SecurityPolicy.Create-Destination-Button
#SecurityPolicy.Create-Destination type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
${URIname} create list zdhftpurl
${FTPContentname} create list zdhftpContent
${FTPAccountname} create list zdhftpAccount
${filter} create list URI Content Account
Create-Application-Button
ApplicationSearch FTP
Create-Filter-judge Application=FTP Filter=${filter} URIname=${URIname} FTPContentname=${FTPContentname} FTPAccountname=${FTPAccountname}
Deny-subaction action=deny subaction=RST
LogSession 1
Enabled open
Security-Policies-OK