1,How to do a UTM demo for customer
2,How to configure the IPS in USG
3,How to test the IPS demo result.
Configure the USG2200 as follows:
Set the IP addresses of the interfaces, define routing polices, and add routes to the routing table.
ip address 192.168.0.1 255.255.255.0
ip address 10.1.1.1 255.255.255.0
firewall zone trust
set priority 85
add interface GigabitEthernet0/0/0
firewall zone untrust
set priority 5
add interface GigabitEthernet0/0/2
firewall policy interzone trust untrust outbound
policy source 10.1.1.0 mask 24
Configure a IPS policy.
Build a policy name “ipstest” for IPS
Enable IPS function and apply it
Enable IPS function in public policy and apply it
Open the http Server and upload IPS file
Use HTTP client to download AV file from HTTP server
Networking in lab environment:
As shown in the following figure, USG firewall have separated two networks.One is 10.1.1.0/24,another is 192.168.0.0/24.The demo is HTTP Client get IPS file from the HTTP server,the file include IPS character.If enabling IPS in USG,and it can detect and block it.The customer can find the warning form USG.