ZyXEL Communications ZLD User Manual

Page of 386
Chapter 22 IDP Commands
ZyWALL (ZLD) CLI Reference Guide
196
22.5.1  Update Signature Examples
These examples show how to enable/disable automatic IDP downloading, schedule updates, display 
the schedule, display the update status, show the (new) updated signature version number, show 
the total number of signatures and show the date/time the signatures were created.  
22.6  IDP Statistics
The following table describes the commands for collecting and displaying IDP statistics. You must 
use the 
configure terminal
 command to enter the configuration mode before you can use 
these commands.
Router# configure terminal
Router(config)# idp signature update signatures
IDP signature update in progress.
Please check system log for future information.
Router(config)# idp update auto
Router(config)# no idp update auto
Router(config)# idp update hourly
Router(config)# idp update daily 10
Router(config)# idp update weekly fri 13
Router(config)# show idp update
auto: yes
schedule: weekly at Friday 13 o'clock
Router(config)# show idp signature update status
current status: IDP signature download failed, do 1 retry at Sat Jan  4 22:47:47  
2003
last update time: 2003-01-01 01:34:39
Router(config)# show idp signature signatures version
version: 1.2000
Router(config)# show idp signature signatures number
signatures: 2000
Router(config)# show idp signature signatures date
date: 2005/11/13 13:56:03
Table 110   
Commands for IDP Statistics
COMMAND
DESCRIPTION
[no] idp statistics collect
Turn the collection of IDP statistics on or off.  
idp statistics flush
Clears the collected statistics.
show idp statistics summary
Displays the collected statistics.
show idp statistics collect
Displays whether the collection of IDP statistics is turned on or off.
show idp statistics ranking 
{signature-name | source | 
destination}
Query and sort the IDP statistics entries by signature name, source IP 
address, or destination IP address.
signature-name
: lists the most commonly detected signatures.
source
: lists the source IP addresses from which the ZyWALL has 
detected the most intrusion attempts. 
destination: 
lists the most common destination IP addresses for 
detected intrusion attempts.