TMS zl Management and Configuration Guide ST.1.0.090213
1-38
Overview
Firewall
\
Figure 1-8. TMS zl Module Integration with NIM
Figure 1-8 shows how the IDS/IPS function on the TMS zl Module sends SNMP
traps to NIM. NIM processes the trap and responds as indicated in its alert and
policy configurations. For example, NIM might track the source of the threat
to its point of connection and take action there—perhaps, ordering a switch
to throttle or block the port to which the offender connects.
For more information, see “Integration with HP ProCurve Network Immunity
Manager” in Chapter 6: “Intrusion Detection and Prevention.”
Firewall
In routing mode, the TMS zl Module firewall filters traffic that it routes
between TMS VLANs. A TMS VLAN is a VLAN that you have assigned to a zone.
The firewall can:
■ Permit or deny traffic according to access policies that you configure
■ Control the amount of bandwidth used by particular types of traffic
■ Create reservations that guarantee that a session will be open for certain
traffic
■ Run attack checks