提交安全策略修改关键字
This commit is contained in:
@@ -56,6 +56,31 @@ SecurityPolicy-Deny-HTTP-MaxCombination-Drop
|
||||
LogSession 1
|
||||
Enabled open
|
||||
Security-Policies-OK
|
||||
sleep 1
|
||||
#修改策略,修改策略相当于再进行一遍新增
|
||||
Comment 修改策略
|
||||
Security-Source Name SecurityPolicy-Deny-HTTP-MaxCombination
|
||||
EditButton
|
||||
Initialize-Policie Deny
|
||||
#新建策略
|
||||
SecurityPolicy.Create-name SecurityPolicy-Deny-SSL-MaxCombination-Drop
|
||||
SecurityPolicy.Create-action deny
|
||||
SecurityPolicy.Create-Source-Button
|
||||
SecurityPolicy.Create-Source type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.2 post=1
|
||||
SecurityPolicy.Create-Destination-Button
|
||||
SecurityPolicy.Create-Destination type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.3 post=1
|
||||
${fqdnname} create list zdhfqdn
|
||||
${filter} create list SNI CN SAN
|
||||
Create-Application-Button
|
||||
ApplicationSearch SSL
|
||||
Create-Filter-judge Application=SSL Filter=${filter} SSLSNIname=${fqdnname} CNname=${fqdnname} SANname=${fqdnname}
|
||||
Deny-subaction action=deny subaction=RST
|
||||
LogSession 1
|
||||
Enabled open
|
||||
Security-Policies-OK
|
||||
Security-Source Name SecurityPolicy-Deny-SSL-MaxCombination-Drop
|
||||
${text} get text xpath=//*[@id="ly-table1-listcontent"]/div/div[3]/table/tbody/tr/td[2]/div/div/p
|
||||
Should Be Equal As Strings ${text} SecurityPolicy-Deny-SSL-MaxCombination-Drop
|
||||
|
||||
SecurityPolicy-Deny-HTTP-MaxCombination-RST
|
||||
#新建对象fqdn
|
||||
@@ -351,6 +376,189 @@ SecurityPolicy-Deny-HTTP-Host-Alert204
|
||||
Security-Policies-OK
|
||||
|
||||
|
||||
SecurityPolicy-Deny-SSL-MaxCombination-Drop
|
||||
#新建对象fqdn
|
||||
Comment 新建对象fqdn
|
||||
CreatePage FQDN single zdhfqdn keywordtext=*www.baidu.com
|
||||
#新建策略
|
||||
Comment 新建策略
|
||||
Menu policys Security Policy
|
||||
SecurityPolicy.CreateButton
|
||||
SecurityPolicy.Create-name SecurityPolicy-Deny-SSL-MaxCombination-Drop
|
||||
SecurityPolicy.Create-action deny
|
||||
SecurityPolicy.Create-Source-Button
|
||||
SecurityPolicy.Create-Source type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
|
||||
#SecurityPolicy.Create-Destination-Button
|
||||
#SecurityPolicy.Create-Destination type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
|
||||
${fqdnname} create list zdhfqdn
|
||||
${filter} create list SNI CN SAN
|
||||
Create-Application-Button
|
||||
ApplicationSearch SSL
|
||||
Create-Filter-judge Application=SSL Filter=${filter} SSLSNIname=${fqdnname} CNname=${fqdnname} SANname=${fqdnname}
|
||||
Deny-subaction action=deny subaction=Drop
|
||||
LogSession 1
|
||||
Enabled open
|
||||
Security-Policies-OK
|
||||
|
||||
SecurityPolicy-Deny-SSL-MaxCombination-RST
|
||||
#新建对象fqdn
|
||||
Comment 新建对象fqdn
|
||||
CreatePage FQDN single zdhfqdn keywordtext=*www.baidu.com
|
||||
#新建策略
|
||||
Comment 新建策略
|
||||
Menu policys Security Policy
|
||||
SecurityPolicy.CreateButton
|
||||
SecurityPolicy.Create-name SecurityPolicy-Deny-SSL-MaxCombination-Drop
|
||||
SecurityPolicy.Create-action deny
|
||||
SecurityPolicy.Create-Source-Button
|
||||
SecurityPolicy.Create-Source type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
|
||||
#SecurityPolicy.Create-Destination-Button
|
||||
#SecurityPolicy.Create-Destination type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
|
||||
${fqdnname} create list zdhfqdn
|
||||
${filter} create list SNI CN SAN
|
||||
Create-Application-Button
|
||||
ApplicationSearch SSL
|
||||
Create-Filter-judge Application=SSL Filter=${filter} SSLSNIname=${fqdnname} CNname=${fqdnname} SANname=${fqdnname}
|
||||
Deny-subaction action=deny subaction=RST
|
||||
LogSession 1
|
||||
Enabled open
|
||||
Security-Policies-OK
|
||||
|
||||
SecurityPolicy-Deny-DNS-MaxCombination-Drop
|
||||
#新建对象fqdn
|
||||
Comment 新建对象fqdn
|
||||
CreatePage FQDN single zdhfqdn keywordtext=*www.baidu.com
|
||||
#新建策略
|
||||
Comment 新建策略
|
||||
Menu policys Security Policy
|
||||
SecurityPolicy.CreateButton
|
||||
SecurityPolicy.Create-name SecurityPolicy-Deny-SSL-MaxCombination-Drop
|
||||
SecurityPolicy.Create-action deny
|
||||
SecurityPolicy.Create-Source-Button
|
||||
SecurityPolicy.Create-Source type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
|
||||
#SecurityPolicy.Create-Destination-Button
|
||||
#SecurityPolicy.Create-Destination type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
|
||||
${fqdnname} create list zdhfqdn
|
||||
${filter} create list QNAME
|
||||
Create-Application-Button
|
||||
ApplicationSearch DNS
|
||||
Create-Filter-judge Application=DNS Filter=${filter} QNAMEname=${fqdnname}
|
||||
Deny-subaction action=deny subaction=Drop
|
||||
LogSession 1
|
||||
Enabled open
|
||||
Security-Policies-OK
|
||||
|
||||
SecurityPolicy-Deny-DNS-MaxCombination-Redirect-A
|
||||
#新建对象fqdn
|
||||
Comment 新建对象fqdn
|
||||
CreatePage FQDN single zdhfqdn keywordtext=*www.baidu.com
|
||||
#新建策略
|
||||
Comment 新建策略
|
||||
Menu policys Security Policy
|
||||
SecurityPolicy.CreateButton
|
||||
SecurityPolicy.Create-name SecurityPolicy-Deny-SSL-MaxCombination-Drop
|
||||
SecurityPolicy.Create-action deny
|
||||
SecurityPolicy.Create-Source-Button
|
||||
SecurityPolicy.Create-Source type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
|
||||
#SecurityPolicy.Create-Destination-Button
|
||||
#SecurityPolicy.Create-Destination type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
|
||||
${fqdnname} create list zdhfqdn
|
||||
${filter} create list QNAME
|
||||
Create-Application-Button
|
||||
ApplicationSearch DNS
|
||||
Create-Filter-judge Application=DNS Filter=${filter} QNAMEname=${fqdnname}
|
||||
Deny-subaction action=deny subaction=Redirect QType=A Avalue=5.5.5.5 Attl=100 CNAMEvalue=www.a.b CNAMEttl=1000
|
||||
LogSession 1
|
||||
Enabled open
|
||||
Security-Policies-OK
|
||||
|
||||
SecurityPolicy-Deny-DNS-MaxCombination-Redirect-AAAA
|
||||
#新建对象fqdn
|
||||
Comment 新建对象fqdn
|
||||
CreatePage FQDN single zdhfqdn keywordtext=*www.baidu.com
|
||||
#新建策略
|
||||
Comment 新建策略
|
||||
Menu policys Security Policy
|
||||
SecurityPolicy.CreateButton
|
||||
SecurityPolicy.Create-name SecurityPolicy-Deny-SSL-MaxCombination-Drop
|
||||
SecurityPolicy.Create-action deny
|
||||
SecurityPolicy.Create-Source-Button
|
||||
SecurityPolicy.Create-Source type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
|
||||
#SecurityPolicy.Create-Destination-Button
|
||||
#SecurityPolicy.Create-Destination type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
|
||||
${fqdnname} create list zdhfqdn
|
||||
${filter} create list QNAME
|
||||
Create-Application-Button
|
||||
ApplicationSearch DNS
|
||||
Create-Filter-judge Application=DNS Filter=${filter} QNAMEname=${fqdnname}
|
||||
Deny-subaction action=deny subaction=Redirect QType=AAAA Avalue=1234::ABCD Attl=100 CNAMEvalue=www.a.b CNAMEttl=1000
|
||||
LogSession 1
|
||||
Enabled open
|
||||
Security-Policies-OK
|
||||
|
||||
SecurityPolicy-Deny-FTP-MaxCombination-Drop
|
||||
#新建对象url
|
||||
Comment 新建对象url
|
||||
CreatePage URL single zdhftpurl keywordtext=*.com
|
||||
#新建Content
|
||||
Comment Content
|
||||
CreatePage Key single zdhftpContent keywordtext=*pppp
|
||||
#新建Account
|
||||
Comment Account
|
||||
CreatePage Key single zdhftpAccount keywordtext=*pppp
|
||||
#新建策略
|
||||
Comment 新建策略
|
||||
Menu policys Security Policy
|
||||
SecurityPolicy.CreateButton
|
||||
SecurityPolicy.Create-name SecurityPolicy-Deny-SSL-MaxCombination-Drop
|
||||
SecurityPolicy.Create-action deny
|
||||
SecurityPolicy.Create-Source-Button
|
||||
SecurityPolicy.Create-Source type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
|
||||
#SecurityPolicy.Create-Destination-Button
|
||||
#SecurityPolicy.Create-Destination type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
|
||||
${URIname} create list zdhftpurl
|
||||
${FTPContentname} create list zdhftpContent
|
||||
${FTPAccountname} create list zdhftpAccount
|
||||
${filter} create list URI Content Account
|
||||
Create-Application-Button
|
||||
ApplicationSearch FTP
|
||||
Create-Filter-judge Application=FTP Filter=${filter} URIname=${URIname} FTPContentname=${FTPContentname} FTPAccountname=${FTPAccountname}
|
||||
Deny-subaction action=deny subaction=Drop
|
||||
LogSession 1
|
||||
Enabled open
|
||||
Security-Policies-OK
|
||||
|
||||
SecurityPolicy-Deny-FTP-MaxCombination-RST
|
||||
#新建对象url
|
||||
Comment 新建对象url
|
||||
CreatePage URL single zdhftpurl keywordtext=*.com
|
||||
#新建Content
|
||||
Comment Content
|
||||
CreatePage Key single zdhftpContent keywordtext=*pppp
|
||||
#新建Account
|
||||
Comment Account
|
||||
CreatePage Key single zdhftpAccount keywordtext=*pppp
|
||||
#新建策略
|
||||
Comment 新建策略
|
||||
Menu policys Security Policy
|
||||
SecurityPolicy.CreateButton
|
||||
SecurityPolicy.Create-name SecurityPolicy-Deny-SSL-MaxCombination-Drop
|
||||
SecurityPolicy.Create-action deny
|
||||
SecurityPolicy.Create-Source-Button
|
||||
SecurityPolicy.Create-Source type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
|
||||
#SecurityPolicy.Create-Destination-Button
|
||||
#SecurityPolicy.Create-Destination type1=Ip CreateOrSearch=Create Add=Address name=zdhip001 ipclienttext1=192.168.100.1 post=1
|
||||
${URIname} create list zdhftpurl
|
||||
${FTPContentname} create list zdhftpContent
|
||||
${FTPAccountname} create list zdhftpAccount
|
||||
${filter} create list URI Content Account
|
||||
Create-Application-Button
|
||||
ApplicationSearch FTP
|
||||
Create-Filter-judge Application=FTP Filter=${filter} URIname=${URIname} FTPContentname=${FTPContentname} FTPAccountname=${FTPAccountname}
|
||||
Deny-subaction action=deny subaction=RST
|
||||
LogSession 1
|
||||
Enabled open
|
||||
Security-Policies-OK
|
||||
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user