All security Events, parameter names, default values and ranges are listed as they were at 2013-01-15, and will be periodically update. Still, this is not something that is changed that often, so it will probably be useful for you!
ARJ_Long_FileName_Detected
pam.content.arj.maxfilename
Default Value: 400
Maximum Value: 65535
Minimum Value: 0
Type: number
ASP_IIS_HTMLEncode
pam.html.asp.parse.enable
Default Value: true
Type: Boolean
Adobe_Flash_Player_SetNALUnit_Exec
pam.quicktime.set.nal.unit.limit
Default Value: 256
Maximum Value: 4294967295
Minimum Value: 8
Type: number
AntiSniff_DNS_Test
pam.flood.antisniffdns.limit
Default Value: 10
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.flood.antisniffdns.interval
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.flood.antisniffdns.size
Default Value: 1
Maximum Value: 1048576
Minimum Value: 1
Type: number
BitTorrent_DHT_AnnouncePeer
pam.parser.BitTorrentDHT.enabled
Default Value: true
Type: Boolean
BitTorrent_DHT_FindNode
pam.parser.BitTorrentDHT.enabled
Default Value: true
Type: Boolean
BitTorrent_DHT_GetPeers
pam.parser.BitTorrentDHT.enabled
Default Value: true
Type: Boolean
BitTorrent_DHT_Ping
pam.parser.BitTorrentDHT.enabled
Default Value: true
Type: Boolean
BrightStor_BackupAgent_Overflow
pam.brightstor.agent.bo
Default Value: 3166
Maximum Value: 4294967295
Minimum Value: 700
Type: number
CA_License_Server_Command_Overflow
pam.ca_licsvr.cmd.size
Default Value: 256
Maximum Value: 65535
Minimum Value: 1
Type: number
CA_License_Server_Request_Bo
pam.ca_licsvr.options.limit
Default Value: 256
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.ca_licsvr.cmd.search.limit
Default Value: 512
Maximum Value: 4294967295
Minimum Value: 512
Type: number
CSS_IE_Flag_Code_Execution
pam.css.flag.strict
Default Value: false
Type: Boolean
CVS_Directory_Double_Free
pam.cvs.request.path.max
Default Value: 2048
Maximum Value: 4294967295
Minimum Value: 0
Type: number
CVS_Request_Argument_Overflow
pam.cvs.request.argument.max
Default Value: 4096
Maximum Value: 4294967295
Minimum Value: 0
Type: number
CVS_Request_EntryLine_Overflow
pam.cvs.request.entryline.max
Default Value: 4096
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.cvs.request.entryline.binary.max
Default Value: 1024
Maximum Value: 4294967295
Minimum Value: 0
Type: number
CVS_Request_Option_Overflow
pam.cvs.request.option.max
Default Value: 1024
Maximum Value: 4294967295
Minimum Value: 0
Type: number
CVS_Request_Path_Overflow
pam.cvs.request.path.max
Default Value: 2048
Maximum Value: 4294967295
Minimum Value: 0
Type: number
CVS_Request_Tag_Overflow
pam.cvs.request.tag.max
Default Value: 1024
Maximum Value: 4294967295
Minimum Value: 0
Type: number
CiscoSccp_Invalid_MessageID
pam.cisco.sccp.message.last
Default Value: 0
Maximum Value: 4294967295
Minimum Value: 0
Type: number
CiscoSccp_Message_Overflow
pam.cisco.sccp.limit
Default Value: 1024
Maximum Value: 100000
Minimum Value: 4
Type: number
Cisco_CallMgrDB_DoS
pam.cisco.cmdb.length.limit
Default Value: 256
Maximum Value: 1000000
Minimum Value: 0
Type: number
Cisco_IOS_IPV4_DoS
pam.flood.cisco.iosipv4dos.ttl
Default Value: 4
Maximum Value: 254
Minimum Value: 1
Type: number
pam.flood.cisco.ios.ipv4dos.limit
Default Value: 10
Maximum Value: 200
Minimum Value: 0
Type: number
Cisco_IOS_OSPF_BO
pam.flood.cisco.ios.ospfbo.size
Default Value: 512
Maximum Value: 1048576
Minimum Value: 1
Type: number
pam.flood.cisco.ios.ospfbo.limit
Default Value: 250
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.flood.cisco.ios.ospfbo.interval
Default Value: 5
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
CoalescerStatistics
pam.statistics.interval
Default Value: 300
Maximum Value: 2592000
Minimum Value: 1
Type: number
Units: seconds
CoalescerStatistics_Cumulative
pam.statistics.interval
Default Value: 300
Maximum Value: 2592000
Minimum Value: 1
Type: number
Units: seconds
Conficker_P2P_Data_Transfer
pam.conficker_p2p.report.interval
Default Value: 30
Maximum Value: 1800
Minimum Value: -2147483648
Type: number
pam.parser.conficker.enabled
Default Value: true
Type: Boolean
Conficker_P2P_Detected
pam.conficker_p2p.report.interval
Default Value: 30
Maximum Value: 1800
Minimum Value: -2147483648
Type: number
pam.parser.conficker.enabled
Default Value: true
Type: Boolean
Conficker_P2P_Exec_Transfer
pam.conficker_p2p.report.interval
Default Value: 30
Maximum Value: 1800
Minimum Value: -2147483648
Type: number
pam.parser.conficker.enabled
Default Value: true
Type: Boolean
Conficker_P2P_Protection
pam.conficker_p2p.report.interval
Default Value: 30
Maximum Value: 1800
Minimum Value: -2147483648
Type: number
pam.parser.conficker.enabled
Default Value: true
Type: Boolean
Content_Analyzer_Credit_Card_Num
pam.ca.credit_card_num.regex
Default Value: [^-0-9.a-zA-Z]((((5[1-5]\d{2})|(6011)|(65\d{2}))[- .]?\d{4}[- .]?\d{4}[- .]?\d{4})|(4\d{3}[- .]?((\d{4}[- .]?\d{4})|(\d{5}))[- .]?\d{4})|(((3[68]\d{2})|(30[0-5]\d))[- .]?\d{6}[- .]?\d{4})|(3[47]\d{2}[- .]?\d{6}[- .]?\d{5}))[^-0-9.a-zA-Z]
Type: string
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.credit_card_num.validate
Default Value: true
Type: Boolean
pam.ca.credit_card_num.minmatch
Default Value: 10
Maximum Value: 4000000000
Minimum Value: 1
Type: number
Content_Analyzer_Date
pam.ca.date.minmatch
Default Value: 100
Maximum Value: 4000000000
Minimum Value: 1
Type: number
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.date.regex
Default Value: [^-0-9./]((([1][012]|0?[1-9])[-./]([3][01]|[12]\d|0?[1-9])[-./]([1-2]\d{3}|\d{2}))|(([3][01]|[12]\d|0?[1-9])[-./]([1][012]|0?[1-9])[-./]([1-2]\d{3}|\d{2})))[^-0-9./]
Type: string
Content_Analyzer_Dollar_Amount
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.dollar_amount.regex
Default Value: [¢$££PR¥]\s*(((\d,?)*\d[,.]\d{2})|([,.]\d{2}))[^-0-9.]
Type: string
pam.ca.dollar_amount.minmatch
Default Value: 100
Maximum Value: 4000000000
Minimum Value: 1
Type: number
Content_Analyzer_Email_Addr
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.email_addr.regex
Default Value: [a-zA-Z0-9]@[A-Za-z0-9]([-.]?[a-zA-Z0-9])+\.[A-Za-z]{2,}[^.A-Za-z0-9]
Type: string
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.email_addr.minmatch
Default Value: 100
Maximum Value: 4000000000
Minimum Value: 1
Type: number
Content_Analyzer_Person_Name
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.person_name.minmatch
Default Value: 100
Maximum Value: 4000000000
Minimum Value: 1
Type: number
pam.ca.person_name.regex
Default Value: ([A-Z][a-z]+,\s[A-Z][a-z]+\s[A-Z](\.)?\s)|((Sr\.?|Sig\.?|ret\.|Capt\.|Maj\.|Col\.|Rev\.?|Sir\.?|Mlles?\.|MM?\.|Mmes?\.|Mr\.?|Mrs\.?|Miss|Ms\.?|Dr\.?)\s[A-Z][-a-z'.])|([A-Z][a-z]+\s[A-Z]\.\s[A-Z][a-z])
Type: string
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
Content_Analyzer_Postal_Addr
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.postal_addr.regex
Default Value: ,\x20*(A[ELKSZRAP]|C[AOT]|D[EC]|F[LM]|G[AU]|HI|I[ADLN]|K[SY]|LA|M[ADEHINOPST]|N[CDEHJMVY]|O[HKR]|P[ARW]|RI|S[CD]|T[NX]|UT|V[AIT]|W[AIVY])\x20+\d{5}(-\d{4})?[^-0-9.]
Type: string
pam.ca.postal_addr.minmatch
Default Value: 100
Maximum Value: 4000000000
Minimum Value: 1
Type: number
Content_Analyzer_Social_Security_Num
pam.ca.social_security_num.minmatch
Default Value: 10
Maximum Value: 4000000000
Minimum Value: 1
Type: number
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.social_security_num.regex
Default Value: [^-0-9.](00[1-9]|0[1-9]\d|[1-6]\d{2}|7[0-6]\d|77[0-2])[- .]([1-9]0|0[1-9]|[1-9][1-9])[- .](\d{3}[1-9]|[1-9]\d{3}|\d[1-9]\d{2}|\d{2}[1-9]\d)[^-0-9.]
Type: string
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
Content_Analyzer_US_Phone_Num
pam.ca.us_phone_num.regex
Default Value: [^-0-9.]((\(\d{3}\)\x20?)|(\d{3}-))?\d{3}-\d{4}[^-0-9.]
Type: string
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.us_phone_num.minmatch
Default Value: 100
Maximum Value: 4000000000
Minimum Value: 1
Type: number
Content_Analyzer_User_Combined_0
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.user_comb_0.reportstr
Default Value: User Combined 0
Type: string
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.user_comb_0.events
Type: string
Content_Analyzer_User_Combined_1
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.user_comb_1.reportstr
Default Value: User Combined 1
Type: string
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.user_comb_1.events
Type: string
Content_Analyzer_User_Combined_2
pam.ca.user_comb_2.reportstr
Default Value: User Combined 2
Type: string
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.user_comb_2.events
Type: string
Content_Analyzer_User_Combined_3
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.user_comb_3.reportstr
Default Value: User Combined 3
Type: string
pam.ca.user_comb_3.events
Type: string
Content_Analyzer_User_Combined_4
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.user_comb_4.events
Type: string
pam.ca.user_comb_4.reportstr
Default Value: User Combined 4
Type: string
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
Content_Analyzer_User_Combined_5
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.user_comb_5.reportstr
Default Value: User Combined 5
Type: string
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.user_comb_5.events
Type: string
Content_Analyzer_User_Combined_6
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.user_comb_6.reportstr
Default Value: User Combined 6
Type: string
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.user_comb_6.events
Type: string
Content_Analyzer_User_Combined_7
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.user_comb_7.reportstr
Default Value: User Combined 7
Type: string
pam.ca.user_comb_7.events
Type: string
Content_Analyzer_User_Defined_0
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.user_def_0.regex
Type: string
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.user_def_0.reportstr
Default Value: User Defined 0
Type: string
pam.ca.user_def_0.minmatch
Default Value: 8
Maximum Value: 4000000000
Minimum Value: 1
Type: number
Content_Analyzer_User_Defined_1
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.user_def_1.regex
Type: string
pam.ca.user_def_1.reportstr
Default Value: User Defined 1
Type: string
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.user_def_1.minmatch
Default Value: 8
Maximum Value: 4000000000
Minimum Value: 1
Type: number
Content_Analyzer_User_Defined_2
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.user_def_2.reportstr
Default Value: User Defined 2
Type: string
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.user_def_2.regex
Type: string
pam.ca.user_def_2.minmatch
Default Value: 8
Maximum Value: 4000000000
Minimum Value: 1
Type: number
Content_Analyzer_User_Defined_3
pam.ca.user_def_3.minmatch
Default Value: 8
Maximum Value: 4000000000
Minimum Value: 1
Type: number
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.user_def_3.regex
Type: string
pam.ca.user_def_3.reportstr
Default Value: User Defined 3
Type: string
Content_Analyzer_User_Defined_4
pam.ca.user_def_4.reportstr
Default Value: User Defined 4
Type: string
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.user_def_4.minmatch
Default Value: 8
Maximum Value: 4000000000
Minimum Value: 1
Type: number
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.user_def_4.regex
Type: string
Content_Analyzer_User_Defined_5
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.user_def_5.minmatch
Default Value: 8
Maximum Value: 4000000000
Minimum Value: 1
Type: number
pam.ca.user_def_5.regex
Type: string
pam.ca.user_def_5.reportstr
Default Value: User Defined 5
Type: string
Content_Analyzer_User_Defined_6
pam.ca.user_def_6.regex
Type: string
pam.ca.user_def_6.minmatch
Default Value: 8
Maximum Value: 4000000000
Minimum Value: 1
Type: number
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
pam.ca.user_def_6.reportstr
Default Value: User Defined 6
Type: string
Content_Analyzer_User_Defined_7
pam.ca.enabled
Default Value: false
Type: Boolean
pam.ca.user_def_7.regex
Type: string
pam.ca.user_def_7.minmatch
Default Value: 8
Maximum Value: 4000000000
Minimum Value: 1
Type: number
pam.ca.zip.uncompress.enable
Default Value: false
Type: Boolean
pam.ca.user_def_7.reportstr
Default Value: User Defined 7
Type: string
pam.ca.report.packetinfo
Default Value: true
Type: Boolean
Content_CMS_OpenSSL_Exec
pam.cms.trigger.without.indefinite.length
Default Value: false
Type: Boolean
Content_Incorrect_Extension
pam.http.report.content.incorrect.extension
Default Value: false
Type: Boolean
Cross_Site_Scripting
pam.injection.xss.suppression
Default Value: false
Type: Boolean
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
DB2_XMLQUERY_Overflow
pam.drda.xmlquery.threshold
Default Value: 264
Maximum Value: 2147483647
Minimum Value: 10
Type: number
DCOM_Large_Body_Extension
pam.dcom.extension.limit
Default Value: 65536
Maximum Value: 4294967295
Minimum Value: 1
Type: number
DHCP_Format_String_BO
pam.dhcp.options.limit
Default Value: 512
Maximum Value: 4294967295
Minimum Value: 1
Type: number
DHCP_Hostname_Overflow
pam.dhcp.hostname.limit
Default Value: 253
Maximum Value: 4294967295
Minimum Value: 1
Type: number
DHCP_Large_Option_Bo
pam.dhcp.options.limit
Default Value: 512
Maximum Value: 4294967295
Minimum Value: 1
Type: number
DHCP_Long_Discover_Message
pam.dhcp.discover.limit
Default Value: 1000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
DNS_Cache_Poison
pam.dns_cache_poison.question.limit
Default Value: 50
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.dns_cache_poison.age.limit
Default Value: 3
Maximum Value: 10
Minimum Value: -2147483648
Type: number
pam.dns_cache_poison.answer.limit
Default Value: 40
Maximum Value: 4294967295
Minimum Value: 2
Type: number
pam.dns_cache_poison.authoritative.only
Default Value: false
Type: Boolean
DNS_Cache_Poison_PortGuessing_Attack
pam.dns_cache_poison.age.limit
Default Value: 3
Maximum Value: 10
Minimum Value: -2147483648
Type: number
pam.dns_cache_poison.repeated.domain.limit
Default Value: 10
Maximum Value: 4294967295
Minimum Value: 2
Type: number
pam.dns_cache_poison.repeated.domain.time
Default Value: 5
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.dns_cache_poison.subdomain.answer.limit
Default Value: 5
Maximum Value: 4294967295
Minimum Value: 2
Type: number
DNS_Cache_Poison_Subdomain_Attack
pam.dns_cache_poison.age.limit
Default Value: 3
Maximum Value: 10
Minimum Value: -2147483648
Type: number
pam.dns_cache_poison.repeated.domain.limit
Default Value: 10
Maximum Value: 4294967295
Minimum Value: 2
Type: number
pam.dns_cache_poison.repeated.domain.time
Default Value: 5
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.dns_cache_poison.subdomain.answer.limit
Default Value: 5
Maximum Value: 4294967295
Minimum Value: 2
Type: number
DNS_Dot_Query
pam.dns_dot_query.report.interval
Default Value: 2
Maximum Value: 100000
Minimum Value: -2147483648
Type: number
DNS_Excessive_Requests
pam.dns.request.count
Default Value: 300
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.dns.request.interval
Default Value: 30
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.dns.requestlimits
Default Value: false
Type: Boolean
DNS_Format_String
pam.dns.maxname
Default Value: 900
Maximum Value: 4294967295
Minimum Value: 1
Type: number
DNS_Generic_Intel_Overflow
pam.shellcode.detection
Default Value: true
Type: Boolean
DNS_Hostname_Overflow
pam.dns.maxname
Default Value: 900
Maximum Value: 4294967295
Minimum Value: 1
Type: number
DNS_Malformed_Flood
pam.flood.dns.size
Default Value: 2048
Maximum Value: 1048576
Minimum Value: 1
Type: number
pam.flood.dns.limit
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.dns.flood.protection
Default Value: false
Type: Boolean
pam.flood.dns.interval
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
DNS_TCP_Port_Abuse
pam.dns.tcp.malformed.abuse.count
Default Value: 3
Maximum Value: 4294967295
Minimum Value: 2
Type: number
pam.tcp.dns.ignore_syn_data
Default Value: true
Type: Boolean
DNS_Tunnel_Detected
pam.dns.tunnel.idle.timeout
Default Value: 3
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.dns.tunnel.detection.total
Default Value: 40
Maximum Value: 65535
Minimum Value: 5
Type: number
pam.dns.tunnel.detection.rate
Default Value: 4
Maximum Value: 65535
Minimum Value: 1
Type: number
pam.dns.tunnel.min.data.length
Default Value: 15
Maximum Value: 32767
Minimum Value: 0
Type: number
pam.dns.tunnel.report.interval
Default Value: 10
Maximum Value: 100000
Minimum Value: -2147483648
Type: number
DNS_Windows_SMTP_Overflow
pam.dns.answer.count
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 1
Type: number
DataProtector_Opcode20_Exec
pam.data_protector.rootquery.limit
Default Value: 1023
Maximum Value: 65535
Minimum Value: 100
Type: number
DataProtector_Opcode27_Exec
pam.data_protector.opcode27.limit
Default Value: 254
Maximum Value: 65535
Minimum Value: 100
Type: number
DataProtector_Root_Query_Exec
pam.data_protector.rootquery.limit
Default Value: 1023
Maximum Value: 65535
Minimum Value: 100
Type: number
EMail_Generic_Intel_Overflow
pam.shellcode.detection
Default Value: true
Type: Boolean
EOT_Compressed_OpenTypeFont_Detected
pam.parser.eot.enabled
Default Value: true
Type: Boolean
EOT_Data_Record_Heap_Overflow
pam.parser.eot.enabled
Default Value: true
Type: Boolean
EOT_Malformed_OpenTypeFont_Detected
pam.parser.eot.enabled
Default Value: true
Type: Boolean
EOT_OpenTypeFont_Detected
pam.parser.eot.enabled
Default Value: true
Type: Boolean
EPS_Long_Comment
pam.eps.comment.length.limit
Default Value: 1024
Maximum Value: 65535
Minimum Value: 0
Type: number
EarthAgent_ServerProtect_TMReg_Overflow
pam.trend_earthagent.tmregstring.limit
Default Value: 256
Maximum Value: 65535
Minimum Value: 1
Type: number
Echo_Reply_Without_Request
pam.icmp.noechorequest.interval
Default Value: 600
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Units: seconds
pam.icmp.noechorequest.count
Default Value: 3
Maximum Value: 409
Minimum Value: 0
Type: number
Email_Auth_CramMd5_Overflow
pam.smtp.auth.crammd5.max
Default Value: 384
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Email_Auth_Failed
pam.login.smtp.count
Default Value: 4
Maximum Value: 409
Minimum Value: 1
Type: number
pam.login.smtp.interval
Default Value: 3600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Email_Auth_Overflow
pam.smtp.auth.max
Default Value: 1000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Email_Autonomy_KeyView_EML_Multiple_Bo
pam.mime.cumulativeheader.limit
Default Value: 3200
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Email_Autonomy_Kvdocve_Bo
pam.content.html.src.max
Default Value: 400
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Email_Calendar_Code_Exec
pam.icalendar.property.binary.limit
Default Value: 64
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.icalendar.property.limit
Default Value: 128
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Email_Command_Overflow
pam.smtp.command.limit
Default Value: 512
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Email_Error
pam.smtp.error.count
Default Value: 10
Maximum Value: 2000
Minimum Value: 1
Type: number
pam.smtp.error.interval
Default Value: 120
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Email_GoodTech_MultipleRcpt_Bo
pam.smtp.maxname
Default Value: 255
Maximum Value: 2147483647
Minimum Value: 1
Type: number
Email_Helo_Overflow
pam.login.maxname
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Email_Mime_Filename_Overflow
pam.mime.filename.limit
Default Value: 256
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Email_Name_Overflow
pam.smtp.maxname
Default Value: 255
Maximum Value: 2147483647
Minimum Value: 1
Type: number
Email_Notes_Attribute_Overflow
pam.content.html.attribute.max
Default Value: 0x400
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Email_Qmail_Rcpt
pam.smtp.qmail.maxrcpt
Default Value: 65535
Maximum Value: 2147483647
Minimum Value: 1
Type: number
Email_Recipient_Overflow
pam.smtp.maxrcpt
Default Value: 1000
Maximum Value: 2147483647
Minimum Value: 1
Type: number
Email_VCF_Mozilla_Overflow
pam.content.vcard.limit
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Email_Virus_Double_Extension
pam.filename.double_extension.require.spaces
Default Value: true
Type: Boolean
Email_Virus_Suspicious_Zip
pam.content.zip.uncompressed.min
Default Value: 128
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Email_Zip_Executable_Content
pam.content.zip.uncompressed.min
Default Value: 128
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.zip_executable.encrypted
Default Value: false
Type: Boolean
Encrypted_Session_Policy_Abuse
pam.encrypted_session.trigger_on_connect
Default Value: true
Type: Boolean
FAX_Coversheet_Shellcode_Detected
pam.faxcover.scan.limit
Default Value: 40000
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
FFF_KeyView_Foliosr_BO
pam.parser.fff.enabled
Default Value: true
Type: Boolean
FTP_Allo_Overflow
pam.ftp.allo.limit
Default Value: 128
Maximum Value: 4294967295
Minimum Value: 3
Type: number
FTP_Append_Very_Long
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
FTP_Auth_Failed
pam.login.ftp.interval
Default Value: 3600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.login.ftp.count
Default Value: 4
Maximum Value: 409
Minimum Value: 1
Type: number
FTP_Cisco_IOS_MKD_BO
pam.ftp.cisco.mkd.maxname
Default Value: 77
Maximum Value: 2147483647
Minimum Value: 32
Type: number
FTP_Cisco_IOS_Multiple_BO
pam.ftp.cisco.mkd.maxname
Default Value: 77
Maximum Value: 2147483647
Minimum Value: 32
Type: number
FTP_Commands_With_Binary
pam.ftp.cmd.binary.count
Default Value: 5
Maximum Value: 2147483647
Minimum Value: 1
Type: number
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
pam.ftp.cmd.count
Default Value: 3
Maximum Value: 2147483647
Minimum Value: 1
Type: number
FTP_Cwd_Overflow
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
FTP_Delete_Very_Long
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
FTP_Filename_Overflow
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
FTP_Generic_Intel_Overflow
pam.shellcode.detection
Default Value: true
Type: Boolean
FTP_Glob_Implementation
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
FTP_List_Long_Line
pam.ftp.list.maxline
Default Value: 1024
Maximum Value: 65535
Minimum Value: 1
Type: number
FTP_Login_Overflow
pam.login.maxname
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 1
Type: number
FTP_Mdtm_Very_Long
pam.ftp.mdtm.limit
Default Value: 478
Maximum Value: 4294967295
Minimum Value: 1
Type: number
FTP_Mkd_Overflow
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
FTP_Mlst_Very_Long
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
FTP_NLST_Overflow
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
FTP_Netware_Delete_Overflow
pam.ftp.netware.delete.maxname
Default Value: 114
Maximum Value: 2147483647
Minimum Value: 32
Type: number
FTP_Oracle_Pass_Overflow
pam.login.maxpass
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 1
Type: number
FTP_PWD_Response_Overflow
pam.ftp.pwd.overflow.threshold
Default Value: 1023
Maximum Value: 65535
Minimum Value: 0
Type: number
FTP_Passive_Response_Very_Long
pam.ftp.pasv.overflow.threshold
Default Value: 60
Maximum Value: 65535
Minimum Value: 1
Type: number
FTP_Passive_Very_Long
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
FTP_Password_Overflow
pam.login.maxpass
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 1
Type: number
FTP_ProFTPD_Username_SQL_Injection
pam.ftp.allowanyserver
Default Value: false
Type: Boolean
FTP_Restart_LargeFile
pam.ftp.rest.limit
Default Value: 4096000000
Maximum Value: 4294967295
Minimum Value: 1000000
Type: number
FTP_Restart_Very_Long
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
FTP_Retr_Very_Long
pam.ftp.retr.limit
Default Value: 478
Maximum Value: 4294967295
Minimum Value: 1
Type: number
FTP_Rmd_Very_Long
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
FTP_Rnfr_Very_Long
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
FTP_Rnto_Very_Long
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
FTP_Size_Very_Long
pam.ftp.size.limit
Default Value: 478
Maximum Value: 4294967295
Minimum Value: 1
Type: number
FTP_Stat_Very_Long
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
FTP_Stor_Very_Long
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
FTP_Unix_Passwd_File_Accessed
pam.passwd.lineskip.count
Default Value: 8
Maximum Value: 4294967295
Minimum Value: 0
Type: number
FTP_Virus_Suspicious_Zip
pam.content.zip.uncompressed.min
Default Value: 128
Maximum Value: 4294967295
Minimum Value: 0
Type: number
FTP_WSFTP_Allo_BO
pam.ftp.allo.max
Default Value: 429496719
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Finger_Generic_Intel_Overflow
pam.shellcode.detection
Default Value: true
Type: Boolean
Flac_Metadata_Block_BO
pam.parser.flac.enabled
Default Value: true
Type: Boolean
Flv_String_Overflow
pam.flv.string.max
Default Value: 0x3FFFFFFF
Maximum Value: 4294967295
Minimum Value: 0
Type: number
HP_DP_Cell_Manager_DoS
pam.hp_dp_cellmgr.max.length
Default Value: 0xFFff
Maximum Value: 0xFFffFFff
Minimum Value: 0
Type: number
HSRP_Invalid_IPTTL
pam.hsrp.ipttl.threshold
Default Value: 3
Maximum Value: 255
Minimum Value: 0
Type: number
HSRP_Suspicious_Priority
pam.hsrp.priority.threshold
Default Value: 255
Maximum Value: 255
Minimum Value: 0
Type: number
HTML_AIM_URL_Overflow
pam.html.aim.url.limit
Default Value: 400
Maximum Value: 2147483647
Minimum Value: 1
Type: number
HTML_Exploit_Fingerprint
pam.fingerprint.token.enabled
Default Value: true
Type: Boolean
HTML_File_URI_Overflow
pam.html.file.uri.limit
Default Value: 512
Maximum Value: 65535
Minimum Value: 0
Type: number
HTML_Hostname_Overflow
pam.html.hostname.limit
Default Value: 250
Maximum Value: 4294967295
Minimum Value: 0
Type: number
HTML_IRC_URL_Overflow
pam.html.irc.url.limit
Default Value: 800
Maximum Value: 2147483647
Minimum Value: 1
Type: number
HTML_Mshtml_Overflow
pam.html.mshtml.bo
Default Value: 1000
Maximum Value: 65535
Minimum Value: 2
Type: number
HTML_Net_Virtual_Method_Delegate
pam.html.net.table.tolerance
Default Value: 80
Maximum Value: 65535
Minimum Value: 0
Type: number
HTML_Object_Styles_Overflow
pam.html.object.styles.max
Default Value: 16
Maximum Value: 65535
Minimum Value: 1
Type: number
HTML_OnLoad_Very_Large
pam.html.body.onload.limit
Default Value: 2048
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTML_UTF8_Overflow
pam.html.utf8.bo
Default Value: 5
Maximum Value: 65535
Minimum Value: 1
Type: number
HTML_VML_Overflow
pam.html.vml.spt.limit
Default Value: 202
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.html.vml.fill.limit
Default Value: 512
Maximum Value: 4294967295
Minimum Value: 0
Type: number
HTTP_ACCEPT_Overflow
pam.http.maxaccept
Default Value: 1600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_Apache_Chunked_BO
pam.http.apache.bo.chunksize
Default Value: 0xE0000000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_Apache_Expect_XSS
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
HTTP_Apache_Header_Memory_DoS
pam.http.header.contspace.limit
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 0
Type: number
HTTP_Apache_ModUserDir_Disclosure
pam.moduser.interval
Default Value: 15
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.moduserdir.count
Default Value: 3
Maximum Value: 409
Minimum Value: 1
Type: number
HTTP_Apache_OnError_XSS
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
HTTP_Apache_Struts2_Exec
pam.struts.any.server.type
Default Value: false
Type: Boolean
HTTP_Auth_Failed
pam.login.http.interval
Default Value: 3600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.login.http.count
Default Value: 4
Maximum Value: 409
Minimum Value: 1
Type: number
HTTP_Auth_TooLong
pam.http.maxauth
Default Value: 500
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_BrownOrifice
pam.content.jar.decompress
Default Value: false
Type: Boolean
HTTP_CRLF_Injection_Response_Splitting
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.argument.token.limit
Default Value: 8
Maximum Value: 100
Minimum Value: 0
Type: number
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
HTTP_Chunked_Encoding_Overflow
pam.http.chunked.encoding.overflow
Default Value: 0x3FFFFFFF
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_Connect_Overflow
pam.http.maxconnect
Default Value: 0x400
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_Connection_Overflow
pam.http.maxconnectionfield
Default Value: 32
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: characters
HTTP_ContentDisposition_LongFile
pam.http.resp.filename.size
Default Value: 500
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_Content_Type_Overflow
pam.http.maxtype
Default Value: 2000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_Cross_Site_Scripting
pam.injection.xss.suppression
Default Value: false
Type: Boolean
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_DotDot
pam.http_dotdot.limit
Default Value: 3
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_Field_With_Binary
pam.http.binary.count
Default Value: 20
Maximum Value: 65535
Minimum Value: 0
Type: number
pam.http.binary.fieldlength
Default Value: 100
Maximum Value: 65535
Minimum Value: 1
Type: number
HTTP_Fields_With_Binary
pam.http.binary.fieldcount
Default Value: 3
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Units: fields
HTTP_Forced_Browsing_Probe
pam.http.fbdetect.count
Default Value: 15
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.http.fbdetect.interval
Default Value: 20
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.fbdetect.ratio
Default Value: 20
Maximum Value: 100
Minimum Value: 0
Type: number
pam.http.forcedbrowsingdetect.enabled
Default Value: false
Type: Boolean
HTTP_GET_ComputeSum
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_GET_CreateTable
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_GET_DotDot_Data
pam.http_get_dotdot_data.limit
Default Value: 3
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_GET_GroupBy
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_GET_SQL_Convert_Int
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_GET_SQL_OpenRowSet
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_GET_SQL_Select_Count
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_GET_SQL_Select_Top_1
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_GET_SQL_UnionAllSelect
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_GET_SQL_UnionSelect
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_GET_SQL_WaitForDelay
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_GET_Very_Long
pam.http.maxget
Default Value: 4000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_GET_XP_Cmdshell
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_GETargscript
pam.injection.xss.suppression
Default Value: false
Type: Boolean
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
HTTP_Generic_Intel_Overflow
pam.shellcode.detection
Default Value: true
Type: Boolean
HTTP_GroupWise_AcceptLang_Overflow
pam.http.groupwise.serverport
Default Value: 8300
Maximum Value: 65535
Minimum Value: 1
Type: number
HTTP_GroupWise_Client_Overflow
pam.http.groupwise.serverport
Default Value: 8300
Maximum Value: 65535
Minimum Value: 1
Type: number
HTTP_Groupwise_WebAccess_GWinter_Bo
pam.http.max_novell_auth
Default Value: 366
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_HOST_Overflow
pam.http.maxhostname
Default Value: 300
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_HTML_Tag_Injection
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_Header_Request_Smuggle
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
HTTP_Html_In_Ref
pam.injection.xss.suppression
Default Value: false
Type: Boolean
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
HTTP_IE_IFrame_BO
pam.content.html.iframe.src.max
Default Value: 239
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.content.html.iframe.name.max
Default Value: 1999
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_IE_InstallEngineCtl_Overflow
pam.http.ie.installenginectl.limit
Default Value: 128
Maximum Value: 1000000
Minimum Value: 0
Type: number
HTTP_IFRAME_Tag_Injection
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_IISHTR_Overflow
pam.http.maxname
Default Value: 1023
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_IIS_ASP_Chunked_Overflow
pam.iis-asp.chunksize
Default Value: 512
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.iis-asp.chunksize
Default Value: 512
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_IIS_ASP_WebResource_Fetch_Error
pam.http_reject.count
Default Value: 450
Maximum Value: 2000
Minimum Value: 100
Type: number
pam.http_reject.interval
Default Value: 10
Maximum Value: 4294967295
Minimum Value: 5
Type: number
HTTP_IIS_FPSE_Debug_Bo
pam.iis.fp30reg.limit
Default Value: 512
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_IIS_Index_Server_Overflow
pam.http.iis.ida.threshold
Default Value: 230
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_IIS_MSSQL_XML_Script
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_IIS_MSSQL_xml
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_IIS_Media_Services
pam.http.nsiislog.chunksize
Default Value: 2000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_IIS_RSA_WebAgent_BO
pam.iis.rsa.limit
Default Value: 1024
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_IIS_Request_Header_DoS
pam.http.iis_request_header_dos.anyserver.allow
Default Value: false
Type: Boolean
HTTP_IIS_Tilde_DoS
pam.http.iis_tilde_dos.anyserver.allow
Default Value: false
Type: Boolean
HTTP_Java
pam.content.jar.decompress
Default Value: false
Type: Boolean
HTTP_Large_Request_Content
pam.http.request.content.limit
Default Value: 24999999
Maximum Value: 4294967295
Minimum Value: 0
Type: number
HTTP_Lighttpd_Header_Overflow
pam.http.lighttpd.hdr.limit
Default Value: 0x0000f000
Maximum Value: 0x7fffffff
Minimum Value: 0x200
Type: number
HTTP_Long_Header_Name
pam.http.header.name.limit
Default Value: 240
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_LotsOf_Byte_Ranges
pam.http.rangerequest.apacheonly
Default Value: true
Type: Boolean
pam.http.rangerequest.limit
Default Value: 100
Maximum Value: 65535
Minimum Value: 0
Type: number
HTTP_MCMS_CrossSiteScripting
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
HTTP_MSIS_Script
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
HTTP_MailEnable_Auth_Overflow
pam.http.auth.mailenable
Default Value: 1024
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_MaxDB_WebDBM_Database_Overflow
pam.http.webdbm.maxdblen
Default Value: 64
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_Mozilla_Domain_Name_Overflow
pam.http.mozilla.domainnamebo.limit
Default Value: 4
Maximum Value: 63
Minimum Value: 1
Type: number
HTTP_Nfuse_Script
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
HTTP_OpenView_NNM_CgiArgs_Overflow
pam.nnm.cgiargs.limit
Default Value: 5120
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_OpenView_NNM_OvAlarm_Overflow
pam.nnm.ovalarm.language.limit
Default Value: 68
Maximum Value: 4096
Minimum Value: 16
Type: number
HTTP_OpenView_NNM_OvSessionMgr_Overflow
pam.nnm.sessionmgr.arg.limit
Default Value: 28
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_Oracle_Weblogic_Connector_BO
pam.http.request.limit
Default Value: 4096
Maximum Value: 65535
Minimum Value: 0
Type: number
HTTP_Oracle_iSQL_Login_Overflow
pam.http.oracle.isql.login.limit
Default Value: 50
Maximum Value: 10000
Minimum Value: 0
Type: number
HTTP_PHP_Memory_Limit
pam.http.php.mem.hdr.limit
Default Value: 64
Maximum Value: 512
Minimum Value: 1
Type: number
HTTP_PHP_Script_Injection
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_PHP_TooMany_Parameters_Array_Overflow
pam.http.php.array_overflow.versioncheck
Default Value: false
Type: Boolean
pam.http.url_values.limit
Default Value: 1000
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
HTTP_POST_ComputeSum
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_POST_CreateTable
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_POST_GroupBy
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_POST_SQL_Convert_Int
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_POST_SQL_OpenRowSet
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_POST_SQL_Select_Count
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_POST_SQL_Select_Top_1
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_POST_SQL_UnionAllSelect
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_POST_SQL_UnionSelect
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_POST_SQL_WaitForDelay
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_POST_Script
pam.injection.xss.suppression
Default Value: false
Type: Boolean
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
HTTP_POST_TooMany_Parameters_DoS
pam.http.post_values.limit
Default Value: 1000
Maximum Value: 4294967295
Minimum Value: 0
Type: number
HTTP_POST_XP_Cmdshell
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_POST_repeated_char
pam.name.maxrepeatedchar
Default Value: 100
Maximum Value: 250
Minimum Value: 2
Type: number
HTTP_Parameter_Abuse
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
HTTP_PhatBot_AgoBot
pam.http.phatbot.contentlength
Default Value: 256000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_Proc_Self_Environ_Probe
pam.injection.procselfenviron.traversal.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
HTTP_QuickTime_Java_Code_Exec
pam.content.jar.decompress
Default Value: false
Type: Boolean
HTTP_QuickTime_RTSP_Response_BO
pam.http.quicktime.response.limit
Default Value: 256
Maximum Value: 512
Minimum Value: 32
Type: number
HTTP_Quicktime_RTSP_Overflow
pam.content.rtsp.src.threshold
Default Value: 299
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_Server_Side_Include_Injection
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
HTTP_Slowloris
pam.http.fragmented.request.limit
Default Value: 120
Maximum Value: 65535
Minimum Value: 0
Type: number
pam.http.slow.request.limit
Default Value: 40
Maximum Value: 65535
Minimum Value: 0
Type: number
pam.http.request.header.time.limit
Default Value: 20
Maximum Value: 65535
Minimum Value: 0
Type: number
HTTP_Squid_NTLM_Password_Bo
pam.http.squid.ntlm.password.limit
Default Value: 24
Maximum Value: 10000
Minimum Value: 0
Type: number
HTTP_Struts_CookieInterceptor_Exec
pam.struts.any.server.type
Default Value: false
Type: Boolean
HTTP_Sun_JRE_Malformed_GIF_BO
pam.content.jar.decompress
Default Value: false
Type: Boolean
HTTP_Swat_AuthBo
pam.http.swat.destport
Default Value: 901
Maximum Value: 65535
Minimum Value: 1
Type: number
HTTP_Twiki_Search_CmdExec
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
HTTP_URL_Many_Slashes
pam.http.url.slashes
Default Value: 200
Maximum Value: 4294967295
Minimum Value: 0
Type: number
HTTP_URL_Name_Very_Long
pam.http.maxname
Default Value: 1023
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_URL_Requests_Too_Often
pam.http.urllimit.count
Default Value: 300
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.urlcount.max
Default Value: 0
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.http.urllimit.interval
Default Value: 30
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_URL_TooMany_Parameters_DoS
pam.http.url_values.limit
Default Value: 1000
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
HTTP_URL_repeated_char
pam.name.maxrepeatedchar
Default Value: 100
Maximum Value: 250
Minimum Value: 2
Type: number
HTTP_Unix_Passwd_File_Accessed
pam.passwd.lineskip.count
Default Value: 8
Maximum Value: 4294967295
Minimum Value: 0
Type: number
HTTP_UserAgent_Too_Long
pam.http.maxuseragent
Default Value: 512
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_WebDAV_Long_Rqst_BO
pam.http.webdavmaxurl
Default Value: 19000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_Web_App_Cmd_Exec
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
HTTP_WhatsUpGold_Instance_Overflow
pam.http.whatsupgold.maxinstancelen
Default Value: 1200
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_eDirectory_Host_Overflow
pam.http.edirectory.serverport
Default Value: 8028
Maximum Value: 65535
Minimum Value: 1
Type: number
HTTP_lotsOfURLs
pam.http.urllimit.count
Default Value: 300
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.http.urllimit.enabled
Aliases: pam.http.urllimits
Default Value: false
Type: Boolean
pam.http.urllimit.interval
Default Value: 30
Maximum Value: 4294967295
Minimum Value: 1
Type: number
HTTP_repeated_character
pam.name.maxrepeatedchar
Default Value: 100
Maximum Value: 250
Minimum Value: 2
Type: number
Helix_DNA_LoadTestPassword_Overflow
pam.rtsp.testpassword.max
Default Value: 64
Maximum Value: 65535
Minimum Value: 8
Type: number
Helix_RealServer_Overflow
pam.rtsp.maxurl
Default Value: 512
Maximum Value: 65535
Minimum Value: 8
Type: number
Helix_Universal_Transport_Overflow
pam.rtsp.transport.max
Default Value: 512
Maximum Value: 65535
Minimum Value: 8
Type: number
ICC_Profile_Tag_Overflow
pam.icc.tagoverflow.threshold
Default Value: 60
Maximum Value: 4294967295
Minimum Value: 0
Type: number
ICMP_Flood
pam.flood.icmp.limit
Aliases: pam.icmp.maxcnt
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.flood.icmp.size
Default Value: 512
Maximum Value: 1048576
Minimum Value: 1
Type: number
pam.flood.icmp.interval
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
ICMP_TCP_MTU_DoS
pam.icmp.pmtud.threshold
Default Value: 82
Maximum Value: 4294967295
Minimum Value: 68
Type: number
ICMP_Unreachable_Storm
pam.icmp.unreachable.interval
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.icmp.unreachable.count
Default Value: 50
Maximum Value: 2000
Minimum Value: 1
Type: number
IDENT_Generic_Intel_Overflow
pam.shellcode.detection
Default Value: true
Type: Boolean
IIS_FTP_Session_Status_DoS
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
IMAP4_Very_Long_Command
pam.imap4.command.limit
Default Value: 512
Maximum Value: 4294967295
Minimum Value: 0
Type: number
IMAP_Auth_Failed
pam.login.imap4.count
Default Value: 4
Maximum Value: 409
Minimum Value: 1
Type: number
pam.login.imap4.interval
Default Value: 3600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
IMAP_CramMD5_Long_Username
pam.imap4.crammd5name.limit
Default Value: 256
Maximum Value: 4294967295
Minimum Value: 0
Type: number
IMAP_Generic_Intel_Overflow
pam.shellcode.detection
Default Value: true
Type: Boolean
IMAP_Literal_Contents_Overflow
pam.imap4.literal.length
Default Value: 128
Maximum Value: 4294967295
Minimum Value: 0
Type: number
IMAP_Literal_Overflow
pam.imap4.literal.limit
Default Value: 0x3FFF
Maximum Value: 4294967295
Minimum Value: 0
Type: number
IMAP_Long_Mbox
pam.imap4.mailbox.limit
Default Value: 256
Maximum Value: 4294967295
Minimum Value: 0
Type: number
IMAP_Long_Password
pam.login.maxpass
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 1
Type: number
IMAP_Tag_Overflow
pam.imap4.tag.limit
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 0
Type: number
IMAP_Too_Many_Connects
pam.imap4.connection.interval
Default Value: 10
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.imap4.connection.count
Default Value: 15
Maximum Value: 2000
Minimum Value: 1
Type: number
IM_File_Xfer_Double_Extension
pam.filename.double_extension.require.spaces
Default Value: true
Type: Boolean
IP_Unknown_Protocol
pam.ip.protocol.
Type: Boolean
IRC_Automated_Client
pam.irc.autoclient.limit
Default Value: 2
Maximum Value: 1048576
Minimum Value: 2
Type: number
pam.irc.autoclient.interval
Default Value: 5
Maximum Value: 1048576
Minimum Value: 2
Type: number
IRC_Generic_Intel_Overflow
pam.shellcode.detection
Default Value: true
Type: Boolean
IRC_Rogue_Session
pam.irc.rogue.proxy.ignore
Default Value: false
Type: Boolean
ISAKMP_Brute_Force
pam.auth.ike.count
Default Value: 180
Maximum Value: 409
Minimum Value: 1
Type: number
pam.auth.ike.interval
Default Value: 30
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
ISAKMP_Certificate_Request_Overflow
pam.isakmp.maxcertificatesize
Default Value: 2048
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Ident_Flood
pam.flood.ident.interval
Default Value: 3
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.flood.ident.size
Default Value: 512
Maximum Value: 1048576
Minimum Value: 1
Type: number
pam.flood.ident.limit
Default Value: 50
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Image_EMF_GDI_Filename_Overflow
pam.content.emf.description.threshold
Default Value: 128
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.content.emf.gdi.filename.threshold
Default Value: 260
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Image_EMF_Long_Description
pam.content.emf.description.threshold
Default Value: 128
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Image_GIF_CompressionError
pam.content.gif.codesize.threshold
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.content.gif.blocksize.threshold
Default Value: 12
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.content.gif.enabled
Default Value: true
Type: Boolean
Image_ICON_Malformed
pam.icon.image.limit
Default Value: 4096
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Image_JPEG_IE_Size_Overflow
pam.jfif.ie_size.threshold
Default Value: 0x10000000
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Inflate_Utilization_Statistics
pam.content.zip.decompress
Default Value: false
Type: Boolean
pam.inflate.statistics.interval
Default Value: 3600
Maximum Value: 4294967295
Minimum Value: 900
Type: number
pam.content.jar.decompress
Default Value: false
Type: Boolean
pam.content.wmz.decompress
Default Value: true
Type: Boolean
Informix_Long_Username_Overflow
pam.informix.long_username.threshold
Default Value: 960
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Informix_Username_Overflow
pam.informix.username.threshold
Default Value: 32
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Itunes_Playlist_Long_URL_Overflow
pam.pls.urlsize
Default Value: 1024
Maximum Value: 4294967295
Minimum Value: 0
Type: number
JavaScript_ActiveXObject_Obfuscation
pam.javascript.activexObfuscate.split.limit
Default Value: 2
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
JavaScript_Double_Escaped_NOOP_Sled
pam.script.shellcode_noop.aggressive
Default Value: true
Type: Boolean
pam.script.shellcode_noop.aggressive
Default Value: true
Type: Boolean
JavaScript_Large_Eval
pam.javascript.unescape.limit
Default Value: 64
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
JavaScript_Large_FromCharCode
pam.javascript.fromcharcode.limit
Default Value: 64
Maximum Value: 4294967295
Minimum Value: 0
Type: number
JavaScript_Large_Unescape
pam.javascript.unescape.limit
Default Value: 64
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
JavaScript_Multiple_Unescape_Eval
pam.script.unescape.eval.limit
Default Value: 32
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
JavaScript_NOOP_Sled
pam.script.shellcode_noop.aggressive
Default Value: true
Type: Boolean
JavaScript_Shellcode_Detected
pam.script.shellcode_noop.aggressive
Default Value: true
Type: Boolean
JavaScript_Suspicious_Hex_String
pam.javascript.suspicious_hex_string.limit
Default Value: 512
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
JavaScript_Unescape_fromCharCode
pam.js_fromcharcode.multi_radix.required
Default Value: false
Type: Boolean
Java_Deserialization_Privilege_Escalation
pam.content.jar.decompress
Default Value: false
Type: Boolean
Java_Getsoundbank_Overflow
pam.content.jar.decompress
Default Value: false
Type: Boolean
Java_Malicious_Applet
pam.java.threat.threshold
Default Value: 4
Maximum Value: 15
Minimum Value: 0
Type: number
pam.content.jar.decompress
Default Value: false
Type: Boolean
Java_Possibly_Malicious_Applet
pam.java.threat.threshold
Default Value: 4
Maximum Value: 15
Minimum Value: 0
Type: number
pam.content.jar.decompress
Default Value: false
Type: Boolean
Java_Sandbox_Breach_Dos
pam.content.jar.decompress
Default Value: false
Type: Boolean
Java_Sandbox_Code_Execution
pam.content.jar.decompress
Default Value: false
Type: Boolean
Java_Scripting_Privilege_Escalation
pam.content.jar.decompress
Default Value: false
Type: Boolean
Java_Untrusted_Object_Execution
pam.content.jar.decompress
Default Value: false
Type: Boolean
Kerberos_Weak_Encryption
pam.kerberos.weak.encryption.3des
Default Value: false
Type: Boolean
LDAP_Auth_Failed
pam.login.ldap.count
Default Value: 5
Maximum Value: 409
Minimum Value: 1
Type: number
pam.login.ldap.interval
Default Value: 1800
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
LDAP_BER_Sequence_Dos
pam.ldap.badber.count
Default Value: 10
Maximum Value: 65535
Minimum Value: 1
Type: number
LDAP_Distinguished_Name_Overflow
pam.ldap.max.distinguished_name
Default Value: 1024
Maximum Value: 12288
Minimum Value: 1
Type: number
LDAP_Filter_Overflow
pam.ldap.max.filter
Default Value: 4096
Maximum Value: 12288
Minimum Value: 1
Type: number
LDAP_Injection
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
LDAP_Long_ASN1_Length
pam.ldap.asn1.length.limit
Default Value: 500000000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
LDAP_Lotus_Domino_OctetString_Heap_Overflow
pam.ldap.addreq.limit
Default Value: 0xFFFFFFE0
Maximum Value: 4294967295
Minimum Value: 1
Type: number
LDAP_Lotus_Domino_OctetString_Overflow
pam.ldap.lotus.string.limit
Default Value: 0xFFFF
Maximum Value: 4294967295
Minimum Value: 1
Type: number
LDAP_Sun_Search_Dos
pam.ldap.max.distinguished_name
Default Value: 1024
Maximum Value: 12288
Minimum Value: 1
Type: number
LHA_File_Path_Overflow
pam.lha.file.path.limit
Default Value: 255
Maximum Value: 1000000
Minimum Value: 0
Type: number
LNK_MsWin_Code_Execution
pam.lnk.mswin_code_exec.local.enable
Default Value: false
Type: Boolean
LPD_Cachefsd_Overflow
pam.lpd.queue.length
Default Value: 1000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
LPD_Delete_DotDot_Traversal
pam.lpd.delete.dotdot.limit
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.lpd.delete.dotdot.limit
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 1
Type: number
LPD_Novell_Iprint_Queuename_Overflow
pam.lpd.iprint.qlen
Default Value: 120
Maximum Value: 4294967295
Minimum Value: 1
Type: number
LPD_SAP_Overflow
pam.lpd.sapbuf.length
Default Value: 450
Maximum Value: 4294967295
Minimum Value: 1
Type: number
LanMan_Share_Enum_Sweep
pam.lanman.shareenumsweep.interval
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.lanman.shareenumsweep.count
Default Value: 5
Maximum Value: 409
Minimum Value: 1
Type: number
Units: seconds
M3U_Long_Filename_Overflow
pam.content.m3u.filename.max
Default Value: 350
Maximum Value: 4294967295
Minimum Value: 4
Type: number
pam.content.m3u.filename.binarycount
Default Value: 5
Maximum Value: 4294967295
Minimum Value: 0
Type: number
M3U_UDP_Filename_Format_String
pam.m3u.filename.fmtspecifiers
Default Value: 5
Maximum Value: 4294967295
Minimum Value: 1
Type: number
MGCP_LongField
pam.mgcp.maxvalue
Default Value: 1024
Maximum Value: 4294967295
Minimum Value: 0
Type: number
MGCP_Long_Endpoint
pam.mgcp.maxendpoint
Default Value: 64
Maximum Value: 4294967295
Minimum Value: 0
Type: number
MGCP_Long_Tid
pam.mgcp.maxtid
Default Value: 16
Maximum Value: 4294967295
Minimum Value: 0
Type: number
MOV_Malicious_HREFTrack
pam.mov.mdat.id.scan
Default Value: 4096
Maximum Value: 0xFFFFFFFF
Minimum Value: 2
Type: number
MSRPC_LLS_Bo
pam.msrpc.llsrpc.limit2
Default Value: 450
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.msrpc.llsrpc.limit1
Default Value: 18
Maximum Value: 4294967295
Minimum Value: 0
Type: number
MSRPC_LSASS_Bo
pam.msrpc.lsass.limit
Default Value: 824
Maximum Value: 1000000
Minimum Value: 0
Type: number
MSRPC_MSMQ_Overflow
pam.msrpc.msmq.limit
Default Value: 100
Maximum Value: 2147483647
Minimum Value: 1
Type: number
MSRPC_Message_Que_Heap_BO
pam.msrpc.message-que-heap.limit
Default Value: 128
Maximum Value: 2147483647
Minimum Value: 1
Type: number
MSRPC_NetDDE_Bo
pam.msrpc.netdde.limit
Default Value: 256
Maximum Value: 1000000
Minimum Value: 0
Type: number
MSRPC_PlugAndPlay_GetDevList_DoS
pam.msrpc.upnp.devlist.limit
Default Value: 1024
Maximum Value: 65535
Minimum Value: 1
Type: number
MSRPC_Race_Heap_Overflow
pam.msrpc.heapdos.req.count
Default Value: 8
Maximum Value: 4294967295
Minimum Value: 1
Type: number
MSRPC_Registry_Request_DoS
pam.msrpc.reg.class.len.limit
Default Value: 512
Maximum Value: 65535
Minimum Value: 1
Type: number
MSRPC_RemoteActivate_Path_BO
pam.msrpc.isystemactivate-path.limit
Default Value: 261
Maximum Value: 261
Minimum Value: 1
Type: number
MSRPC_Share_Enum_Sweep
pam.msrpc.shareenumsweep.count
Default Value: 5
Maximum Value: 409
Minimum Value: 1
Type: number
pam.msrpc.shareenumsweep.interval
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
MSRPC_Spoolss_GetDocPrinter_Exec
pam.msrpc.spoolss.getdocprinter.exeonly
Default Value: true
Type: Boolean
MSRPC_Spoolss_GetPrinterData_DoS
pam.msrpc.spoolss.getprinterdata.limit
Default Value: 128000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
MSRPC_Spoolss_Overflow
pam.msrpc.spoolss.limit
Default Value: 259
Maximum Value: 65535
Minimum Value: 1
Type: number
MS_Compressed_Folders_Overflow
pam.content.zip.filename.max
Default Value: 260
Maximum Value: 32766
Minimum Value: 0
Type: number
MS_Excel_XLSX_Parsing_Exec
pam.content.zip.decompress
Default Value: false
Type: Boolean
Malformed_Packet_Storm
pam.flood.badpacket.limit
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.flood.badpacket.size
Default Value: 512
Maximum Value: 1048576
Minimum Value: 1
Type: number
pam.ip.protocol.
Type: Boolean
pam.flood.badpacket.interval
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
McAfee_Ebiz_Packet_Code_Execution
pam.parser.McafeeEBiz.enabled
Default Value: true
Type: Boolean
Microsoft_Windows_Shell_Banner
pam.ms_shell_banner.ignore.telnet
Default Value: false
Type: Boolean
Mime_Autonomy_SDK_ContentType_Bo
pam.mime.contenttype.limit
Default Value: 139
Maximum Value: 4294967295
Minimum Value: 0
Type: number
MySQL_Brute_Force
pam.login.mysql.interval
Default Value: 60
Maximum Value: 65000
Minimum Value: 1
Type: number
Units: seconds
pam.login.mysql.count
Default Value: 100
Maximum Value: 2000
Minimum Value: 1
Type: number
MySQL_Change_User_Auth_Bypass
pam.mysql.change.user.fail.limit
Default Value: 5
Maximum Value: 1000000
Minimum Value: 0
Type: number
NDMP_Oracle_SecureBackup_Overflow
pam.ndmp.username.len
Default Value: 1872
Maximum Value: 4294967295
Minimum Value: 1
Type: number
NDMP_Veritas_BackupExec_Auth_Overflow
pam.ndmp.passwdlen
Default Value: 256
Maximum Value: 4294967295
Minimum Value: 1
Type: number
NNTP_From_Overflow
pam.nntp.max.from
Default Value: 255
Maximum Value: 4294967295
Minimum Value: 1
Type: number
NTP_Mode7_DoS
pam.ntp.mode7.count
Default Value: 10
Maximum Value: 200
Minimum Value: 1
Type: number
pam.ntp.mode7.interval
Default Value: 20
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
NTP_Time
pam.sntp.drift.threshold
Default Value: 604800
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Units: seconds
Nachi_Ping_Protection
pam.icmp.nachi.report.interval
Default Value: 300
Maximum Value: 4294967295
Minimum Value: 30
Type: number
pam.icmp.nachi_ping_protection.relaxed
Default Value: false
Type: Boolean
Nachi_Ping_Sweep
pam.icmp.nachi.sleep
Default Value: 300
Maximum Value: 2147483647
Minimum Value: 0
Type: number
Netbios_Flood_DoS
pam.flood.netbios.limit
Default Value: 1000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.flood.netbios.size
Default Value: 2048
Maximum Value: 1048576
Minimum Value: 1
Type: number
pam.flood.netbios.interval
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
Netbios_Name_Scan
pam.dns.netbiosscan.interval
Default Value: 15
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.dns.netbiosscan.count
Default Value: 50
Maximum Value: 2000
Minimum Value: 1
Type: number
Network_Normal
pam.adapter.
Type: string
pam.traffic.sample.interval
Default Value: 60
Maximum Value: 86400
Minimum Value: 1
Type: number
Units: seconds
pam.traffic.sample
Default Value: false
Type: Boolean
pam.traffic.bucket.size
Aliases: pam.traffic.window.size
Default Value: 10
Maximum Value: 86400
Minimum Value: 1
Type: number
Units: seconds
Network_Quiet
pam.adapter.
Type: string
pam.traffic.sample.interval
Default Value: 60
Maximum Value: 86400
Minimum Value: 1
Type: number
Units: seconds
pam.traffic.sample
Default Value: false
Type: Boolean
pam.traffic.bucket.size
Aliases: pam.traffic.window.size
Default Value: 10
Maximum Value: 86400
Minimum Value: 1
Type: number
Units: seconds
OSPF_Database_Desc
pam.ospf.dbdesc.report.limit
Default Value: 86400
Maximum Value: 2147483647
Minimum Value: 1
Type: number
OSPF_Database_Desc_Multicast
pam.ospf.dbdesc.report.limit
Default Value: 86400
Maximum Value: 2147483647
Minimum Value: 1
Type: number
OSPF_Hello
pam.ospf.hello.report.limit
Default Value: 86400
Maximum Value: 2147483647
Minimum Value: 1
Type: number
OSPF_Hello_Multicast
pam.ospf.hello.report.limit
Default Value: 86400
Maximum Value: 2147483647
Minimum Value: 1
Type: number
OSPF_Link_State_Ack
pam.ospf.lsa.report.limit
Default Value: 86400
Maximum Value: 2147483647
Minimum Value: 1
Type: number
OSPF_Link_State_Ack_Multicast
pam.ospf.lsa.report.limit
Default Value: 86400
Maximum Value: 2147483647
Minimum Value: 1
Type: number
OSPF_Link_State_Update
pam.ospf.lsu.report.limit
Default Value: 86400
Maximum Value: 2147483647
Minimum Value: 1
Type: number
OSPF_Link_State_Update_Multicast
pam.ospf.lsu.report.limit
Default Value: 86400
Maximum Value: 2147483647
Minimum Value: 1
Type: number
OSPF_Lnk_State_Req
pam.ospf.lsr.report.limit
Default Value: 86400
Maximum Value: 2147483647
Minimum Value: 1
Type: number
OSPF_Lnk_State_Req_Multicast
pam.ospf.lsr.report.limit
Default Value: 86400
Maximum Value: 2147483647
Minimum Value: 1
Type: number
Oracle_AQELM_Overflow
pam.tns.aqelm.limit
Default Value: 255
Maximum Value: 1000000
Minimum Value: 0
Type: number
Oracle_Admin_SdoCodeSize_Bo
pam.tns.sdocodesize.limit
Default Value: 25
Maximum Value: 1000000
Minimum Value: 0
Type: number
Oracle_Ctxsys_Drvdisp_Overflow
pam.tns.ctxsys.drvdisp.limit
Default Value: 32
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Oracle_Default_Username
pam.oracle.sysaccounts.ignore
Default Value: false
Type: Boolean
Oracle_DropSiteInstant_Bo
pam.tns.dropsiteinstant.limit
Default Value: 256
Maximum Value: 1000000
Minimum Value: 0
Type: number
Oracle_GenReplSupport_Bo
pam.tns.genreplsupport.limit
Default Value: 600
Maximum Value: 1000000
Minimum Value: 0
Type: number
Oracle_Init_Stored_Procedure_Overflow
pam.tns.init.arg.limit
Default Value: 110
Maximum Value: 1000000
Minimum Value: 0
Type: number
Oracle_InstantiateOffline_Bo
pam.tns.instantiateonoffline.limit
Default Value: 256
Maximum Value: 1000000
Minimum Value: 0
Type: number
Oracle_InstantiateOnline_Bo
pam.tns.instantiateonoffline.limit
Default Value: 256
Maximum Value: 1000000
Minimum Value: 0
Type: number
Oracle_InterConvFuncts_Bo
pam.tns.interconvfuncts.limit
Default Value: 30
Maximum Value: 1000000
Minimum Value: 0
Type: number
Oracle_Listener_Bo
pam.tns.cmd.limit
Default Value: 1000
Maximum Value: 1000000
Minimum Value: 0
Type: number
Oracle_LotsOf_Remote_Registration
pam.tns.registration.session.count
Default Value: 20
Maximum Value: 2000
Minimum Value: 1
Type: number
pam.tns.registration.session.interval
Default Value: 300
Maximum Value: 4294967295
Minimum Value: 5
Type: number
Oracle_MD2_SdoCodeSize_Bo
pam.tns.sdocodesize.limit
Default Value: 25
Maximum Value: 1000000
Minimum Value: 0
Type: number
Oracle_MD2_ValidateGeom_Bo
pam.tns.validategeom.limit
Default Value: 25
Maximum Value: 1000000
Minimum Value: 0
Type: number
Oracle_Olap_Table_Overflow
pam.tns.olap.table.limit
Default Value: 303
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Oracle_PitrigDrop_Overflow
pam.tns.pitrigdrop.limit
Default Value: 2337
Maximum Value: 1000000
Minimum Value: 0
Type: number
Oracle_PitrigTruncate_Overflow
pam.tns.pitrigtruncate.limit
Default Value: 1896
Maximum Value: 1000000
Minimum Value: 0
Type: number
Oracle_SnapInternal_Overflow
pam.tns.snapinternal.limit
Default Value: 46
Maximum Value: 1000000
Minimum Value: 0
Type: number
Oracle_TNS_Remote_Registration
pam.tns.registration.data.scan.start
Default Value: 200
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Oracle_ToChar_Bo
pam.tns.tochar.limit
Default Value: 128
Maximum Value: 1000000
Minimum Value: 0
Type: number
Oracle_Too_Many_Useless_Sessions
pam.tns.useless.session.data.requests
Default Value: 2
Maximum Value: 10
Minimum Value: 0
Type: number
pam.tns.useless.session.data.responses
Default Value: 2
Maximum Value: 10
Minimum Value: 0
Type: number
pam.tns.useless.session.interval
Default Value: 30
Maximum Value: 4294967295
Minimum Value: 5
Type: number
pam.tns.useless.session.count
Default Value: 10
Maximum Value: 2000
Minimum Value: 1
Type: number
Oracle_TransformLayer_Overflow
pam.tns.transformlayer.limit
Default Value: 460
Maximum Value: 1000000
Minimum Value: 0
Type: number
Oracle_Username_Bo
pam.tns.username.limit
Default Value: 600
Maximum Value: 1000000
Minimum Value: 0
Type: number
Oracle_XMLSchema_Overflow
pam.tns.xmlschema.limit
Default Value: 64
Maximum Value: 1000000
Minimum Value: 0
Type: number
PAM_Configuration_Error
pam.report.config.error
Default Value: true
Type: Boolean
PDE_Renew_Host
pam.pde.host.renew.age
Default Value: 300
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.pde.enabled
Default Value: false
Type: Boolean
pam.pde.secret
Type: string
pam.pde.validate.time
Default Value: true
Type: Boolean
pam.pde.host.remove.age
Default Value: 3600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.pde.drop.auth.packet
Default Value: true
Type: Boolean
PDE_Unauthenticated_Host
pam.pde.unauth.report.interval
Default Value: 60
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.pde.whitelist
Type: string
pam.pde.enabled
Default Value: false
Type: Boolean
pam.pde.vpn.range
Type: string
pam.pde.host.remove.age
Default Value: 3600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.pde.max.hosts.allow
Default Value: 1000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
PDF_Deep_Nesting
pam.pdf.embedded.parse.depth
Default Value: 3
Maximum Value: 255
Minimum Value: 0
Type: number
PDF_Degenerate_Stream
pam.pdf.trust.length
Default Value: true
Type: Boolean
PDF_Embedded_PDF
pam.pdf.embedded.parse.depth
Default Value: 3
Maximum Value: 255
Minimum Value: 0
Type: number
PDF_FoxIt_Launch_Overflow
pam.pdf.launch.limit
Default Value: 511
Maximum Value: 65535
Minimum Value: 0
Type: number
pam.pdf.scan.limit
Default Value: 80000
Maximum Value: 4294967295
Minimum Value: 0
Type: number
PDF_FoxIt_Title_Overflow
pam.pdf.scan.limit
Default Value: 80000
Maximum Value: 4294967295
Minimum Value: 0
Type: number
PDF_Invalid_Stream_Length
pam.pdf.trust.length
Default Value: true
Type: Boolean
PDF_Swf_Detected
pam.pdf.swf.limit
Default Value: 1
Maximum Value: 65535
Minimum Value: 0
Type: number
PGM_Detected
pam.pgm.report.limit
Default Value: 600
Maximum Value: 2147483647
Minimum Value: 1
Type: number
POP3_Auth_Failed
pam.login.pop3.count
Default Value: 4
Maximum Value: 409
Minimum Value: 1
Type: number
pam.login.pop3.interval
Default Value: 3600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
POP_APOP_Name_Overflow
pam.login.maxname
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 1
Type: number
POP_Filename_Overflow
pam.mime.filename.limit
Default Value: 256
Maximum Value: 4294967295
Minimum Value: 0
Type: number
POP_Fold_Overflow
pam.pop.fold.threshold
Default Value: 128
Maximum Value: 65535
Minimum Value: 0
Type: number
POP_Fuseware_Overflow
pam.pop.fuseware.threshold
Default Value: 1024
Maximum Value: 65535
Minimum Value: 0
Type: number
POP_Generic_Intel_Overflow
pam.shellcode.detection
Default Value: true
Type: Boolean
POP_List_Overflow
pam.pop.list.threshold
Default Value: 1000
Maximum Value: 65535
Minimum Value: 0
Type: number
POP_QPopUser_Overflow
pam.pop.qpopuser.threshold
Default Value: 63
Maximum Value: 65535
Minimum Value: 0
Type: number
POP_Response_Client_Bo
pam.pop.preresponse.max
Default Value: 128
Maximum Value: 4294967294
Minimum Value: 1
Type: number
POP_Retr_DoS
pam.pop.retr.threshold
Default Value: 11
Maximum Value: 65535
Minimum Value: 0
Type: number
POP_SilentRunner_Pass_Overflow
pam.pop.silentrunner.pass.threshold
Default Value: 175
Maximum Value: 65535
Minimum Value: 0
Type: number
POP_SilentRunner_User_Overflow
pam.pop.silentrunner.user.threshold
Default Value: 175
Maximum Value: 65535
Minimum Value: 0
Type: number
POP_Too_Many_Connects
pam.pop.connection.count
Default Value: 15
Maximum Value: 2000
Minimum Value: 1
Type: number
pam.pop.connection.interval
Default Value: 10
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.pop.connection.serverresponse
Default Value: server ready
Type: string
POP_YPOPs_Overflow
pam.pop.yahoo.threshold
Default Value: 180
Maximum Value: 65535
Minimum Value: 0
Type: number
PPTP_Badmagic
pam.parser.pptp.enabled
Default Value: true
Type: Boolean
PPTP_PoPToP_Ctrl_Packet_BO
pam.parser.pptp.enabled
Default Value: true
Type: Boolean
Pict_UncompressedQuickTime_Underflow
pam.pict.uncompressedquicktime.min
Default Value: 0x33
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Ping_Flood
pam.icmp.pingflood.interval
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Units: seconds
pam.icmp.pingflood.count
Default Value: 20
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Poison_Ivy_CnC
pam.poison.ivy.detection.threshold
Default Value: 3
Maximum Value: 20
Minimum Value: 1
Type: number
pam.poison.ivy.inspection.limit
Default Value: 15
Maximum Value: 100
Minimum Value: 4
Type: number
Proxy_Bounce_Deep
pam.proxyparse.enabled
Default Value: true
Type: Boolean
pam.proxyparse.bouncedepth
Default Value: 3
Maximum Value: 65535
Minimum Value: 0
Type: number
QuickTime_OBJI_Overflow
pam.mov.mdat.id.scan
Default Value: 4096
Maximum Value: 0xFFFFFFFF
Minimum Value: 2
Type: number
QuickTime_VR_Panoramic_Sample_Overflow
pam.mov.mdat.id.scan
Default Value: 4096
Maximum Value: 0xFFFFFFFF
Minimum Value: 2
Type: number
RAM_Domain_Overflow
pam.content.ram.domain.max
Default Value: 128
Maximum Value: 4294967295
Minimum Value: 1
Type: number
RAS_RRQ_Low_Time_To_Live
pam.ras.rrq.ttl.min
Default Value: 30
Maximum Value: 4294967295
Minimum Value: 1
Type: number
RAT_Content_Advisor_Overflow
pam.rat.scan.limit
Default Value: 1024
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.rat.name.limit
Default Value: 256
Maximum Value: 4294967295
Minimum Value: 0
Type: number
RDP_Brute_Force
pam.login.rdp.count
Default Value: 15
Maximum Value: 200
Minimum Value: 1
Type: number
pam.login.rdp.interval
Default Value: 60
Maximum Value: 65000
Minimum Value: 1
Type: number
Units: seconds
RDP_Login_Read_Overflow
pam.rdp.login.name.max
Default Value: 256
Maximum Value: 32000
Minimum Value: 1
Type: number
RIP_Add
pam.rip.table
Default Value: 256
Maximum Value: 4294967295
Minimum Value: 11
Type: number
RIP_Expire
pam.rip.table
Default Value: 256
Maximum Value: 4294967295
Minimum Value: 11
Type: number
RIP_Metric_Change
pam.rip.table
Default Value: 256
Maximum Value: 4294967295
Minimum Value: 11
Type: number
RPC_Generic_Intel_Overflow
pam.shellcode.detection
Default Value: true
Type: Boolean
RPC_NFS_Guess
pam.flood.nfsguess.size
Default Value: 64
Maximum Value: 1048576
Minimum Value: 1
Type: number
pam.flood.nfsguess.limit
Default Value: 20
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.flood.nfsguess.interval
Default Value: 3
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
RPC_NFS_NLM_CallerName_Overflow
pam.rpc.nlm.callernamelen
Default Value: 1024
Maximum Value: 4294967295
Minimum Value: 0
Type: number
RTSP_Content_Type_Overflow
pam.rtsp.contenttype.max
Default Value: 255
Maximum Value: 65535
Minimum Value: 8
Type: number
RTSP_Suspicious_Header
pam.rtsp.header.max
Default Value: 1024
Maximum Value: 65535
Minimum Value: 16
Type: number
Radius_Generic_Intel_Overflow
pam.shellcode.detection
Default Value: true
Type: Boolean
Radius_Password_Buffer_Overflow
pam.radius.pass.max
Default Value: 32
Maximum Value: 2147483647
Minimum Value: 1
Type: number
Radius_User_Buffer_Overflow
pam.radius.user.max
Default Value: 46
Maximum Value: 2147483647
Minimum Value: 1
Type: number
Realwin_Scada_Fcinfotagsetcontrol_Bo
pam.parser.RealwinScada.enabled
Default Value: true
Type: Boolean
Realwin_Scada_HMI_Integer_Overflow
pam.parser.RealwinScada.enabled
Default Value: true
Type: Boolean
Realwin_Scada_HMI_Multiple_Overflow
pam.parser.RealwinScada.enabled
Default Value: true
Type: Boolean
Realwin_Scada_String_Overflow
pam.parser.RealwinHmi.enabled
Default Value: true
Type: Boolean
Rlogin_Auth_Failed
pam.login.rlogin.interval
Default Value: 3600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.login.rlogin.count
Default Value: 4
Maximum Value: 409
Minimum Value: 1
Type: number
Rlogin_Name_Very_Long
pam.login.maxname
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Rlogin_Password_Overflow
pam.login.maxpass
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Rlogin_TERM_Very_Long
pam.login.maxname
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 1
Type: number
SDP_Ansi_Escape
pam.content.sdp.ansifield.limit
Default Value: 2
Maximum Value: 65535
Minimum Value: 0
Type: number
SDP_Long_Value
pam.content.sdp.textvalue.limit
Default Value: 1024
Maximum Value: 65535
Minimum Value: 0
Type: number
SIP_Auth_Failed
pam.login.sip.interval
Default Value: 3600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.login.sip.count
Default Value: 4
Maximum Value: 409
Minimum Value: 1
Type: number
SIP_Authenticate_Parameter
pam.sip.qop.limit
Default Value: 31
Maximum Value: 65535
Minimum Value: 2
Type: number
SIP_Contact_Overflow
pam.sip.contact.limit
Default Value: 1000
Maximum Value: 65535
Minimum Value: 1
Type: number
SIP_Large_Content_Length
pam.sip.content.length.max
Default Value: 0xFFFF
Maximum Value: 4294967295
Minimum Value: 1
Type: number
SIP_Large_Max_Forwards
pam.sip.maxforwards.limit
Default Value: 70
Maximum Value: 65535
Minimum Value: 1
Type: number
SIP_Long_Header_Name
pam.sip.header.name.limit
Default Value: 240
Maximum Value: 4294967295
Minimum Value: 1
Type: number
SIP_Long_Header_Value
pam.sip.header.value.limit
Default Value: 1000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
SIP_Long_Method_Name
pam.sip.method.limit
Default Value: 12
Maximum Value: 65535
Minimum Value: 3
Type: number
SIP_Long_Request_URI
pam.sip.uri.limit
Default Value: 1000
Maximum Value: 65535
Minimum Value: 1
Type: number
SIP_Long_Via_Host
pam.sip.hostname.limit
Default Value: 63
Maximum Value: 65535
Minimum Value: 1
Type: number
SIP_Unregistered_Endpoint_Invite
pam.sip.registereduri.max
Default Value: 0
Maximum Value: 2097152
Minimum Value: 0
Type: number
SMB_AccountName_Overflow
pam.smb.account.length
Default Value: 64
Maximum Value: 999
Minimum Value: 1
Type: number
SMB_Auth_Failed
pam.login.smb.interval
Default Value: 3600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.login.smb.count
Default Value: 4
Maximum Value: 409
Minimum Value: 1
Type: number
SMB_Filename_Overflow
pam.smb.filename.max
Default Value: 200
Maximum Value: 2147483647
Minimum Value: 1
Type: number
SMB_Guessable_Password
pam.smb.password.guesses
Type: string
SMB_Malformed
pam.smb.malformed.interval
Default Value: 3600
Maximum Value: 2147483647
Minimum Value: 0
Type: number
SMB_Mass_Login
pam.mass.login.smb.interval
Default Value: 10
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.mass.login.smb.count
Default Value: 20
Maximum Value: 409
Minimum Value: 1
Type: number
SMB_MaxBuffer_Bo
pam.smb.maxbufferbo.threshold
Default Value: 16384
Maximum Value: 4294967295
Minimum Value: 1
Type: number
SMB_NTLM_ExtendedSec_Privilege_Escalation
pam.smb.ntlm.entropy.interval
Default Value: 5
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.smb.ntlm.entropy.count
Default Value: 200
Maximum Value: 500
Minimum Value: 1
Type: number
SMB_Password_Overflow
pam.login.maxpass
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 1
Type: number
SMB_Sam_File
pam.smb.sam.response
Default Value: false
Type: Boolean
SMB_Service_Sweep
pam.tcp.sweep.syn
Default Value: false
Type: Boolean
SMB_Transaction_Response_Overflow
pam.smb.transaction.overflow.allowance
Default Value: 2
Maximum Value: 100
Minimum Value: -2147483648
Type: number
SMB_Unicode_Filename_Overflow
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
SMTP_BDAT_Large_Chunk
pam.smtp.bdat.max.chunk
Default Value: 0x3FFFFFFF
Maximum Value: 4294967295
Minimum Value: 1
Type: number
SMTP_Command_Binary_Overflow
pam.smtp.command.limit
Default Value: 512
Maximum Value: 4294967295
Minimum Value: 0
Type: number
SMTP_Etrn_Overflow
pam.smtp.maxetrn
Default Value: 256
Maximum Value: 4294967295
Minimum Value: 1
Type: number
SMTP_Exchange_Verb_DoS
pam.smtp.exchverb.limit
Default Value: 0x1000000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
SMTP_NTLM_Auth_Generic_Overflow
pam.smtp.ntlm.auth.max
Default Value: 1000
Maximum Value: 65535
Minimum Value: 36
Type: number
SMTP_ParseAddr_Overflow
pam.smtp.charpaircount
Default Value: 2
Maximum Value: 4294967295
Minimum Value: 1
Type: number
SMTP_Relay_Not_Allowed
pam.smtp.relay.count
Default Value: 15
Maximum Value: 409
Minimum Value: 1
Type: number
pam.smtp.relay.interval
Default Value: 10
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
SMTP_Too_Many_Connects
pam.smtp.connection.interval
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.smtp.connection.count
Default Value: 200
Maximum Value: 2000
Minimum Value: 1
Type: number
SMTP_User_Unknown
pam.smtp.userunknown.count
Default Value: 15
Maximum Value: 409
Minimum Value: 1
Type: number
pam.smtp.userunknown.serverresponse
Default Value: User unknown
Type: string
pam.smtp.userunknown.interval
Default Value: 10
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
SNMP_BulkRqst_DoS
pam.snmp.maxrepetitions.limit
Default Value: 1001
Maximum Value: 4294967295
Minimum Value: 0
Type: number
SNMP_Community_Overflow
pam.snmp.community.limit
Default Value: 64
Maximum Value: 65535
Minimum Value: 8
Type: number
SNMP_Crack
pam.snmp.timeout
Default Value: 604800
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
SNMP_Nagios_Plugins_CheckSNMP_BO
pam.snmp.nagios.checksnmp.limit
Default Value: 8192
Maximum Value: 4294967295
Minimum Value: 256
Type: number
SNMP_Suspicious_Version_Size
pam.snmp.max.version
Default Value: 3
Maximum Value: 65535
Minimum Value: 2
Type: number
SNMP_Unsupported_Version
pam.snmp.max.version
Default Value: 3
Maximum Value: 65535
Minimum Value: 2
Type: number
SNMP_V3_HMAC_Security_Bypass
pam.snmp.hmac.minsize
Default Value: 6
Maximum Value: 32767
Minimum Value: 1
Type: number
SOAP_Envelope_Overflow
pam.content.soap.limit
Default Value: 1048576
Maximum Value: 4294967295
Minimum Value: 0
Type: number
SOCKS_Authentication_Malformed
pam.socks.auth.limit
Default Value: 512
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
SOCKS_ShellCode_Detected
pam.socks.shellcode.limit
Default Value: 8192
Maximum Value: 4294967295
Minimum Value: 0
Type: number
SQL_Auth_Failed
pam.login.sql.count
Default Value: 4
Maximum Value: 409
Minimum Value: 1
Type: number
pam.login.sql.count
Default Value: 4
Maximum Value: 409
Minimum Value: 1
Type: number
pam.login.sql.interval
Default Value: 3600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.login.sql.interval
Default Value: 3600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
SQL_Injection
pam.injection.sql.chaff.limit
Default Value: -1
Maximum Value: 1000
Minimum Value: -1
Type: number
pam.injection.sql.score
Default Value: 4
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.sql.boolean.triggers
Default Value: 1
Maximum Value: 2
Minimum Value: 0
Type: number
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.injection.argument.token.limit
Default Value: 8
Maximum Value: 100
Minimum Value: 0
Type: number
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.sql.pedantic
Default Value: false
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
SQL_Injection_Declare_Exec
pam.injection.sql.chaff.limit
Default Value: -1
Maximum Value: 1000
Minimum Value: -1
Type: number
pam.injection.sql.score
Default Value: 4
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.sql.boolean.triggers
Default Value: 1
Maximum Value: 2
Minimum Value: 0
Type: number
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.injection.argument.token.limit
Default Value: 8
Maximum Value: 100
Minimum Value: 0
Type: number
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.sql.pedantic
Default Value: false
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
SQL_Injection_MySQL_Benchmark
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
SQL_Jet_Query_Overflow
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
SQL_SSRP_HeapBo
pam.ssrp.heapbo.threshold
Default Value: 96
Maximum Value: 2147483647
Minimum Value: 1
Type: number
SQL_SSRP_Slammer_Worm
pam.udp.slammer.drop
Default Value: true
Type: Boolean
SQL_SSRP_StackBo
pam.ssrp.stackbo.threshold
Default Value: 96
Maximum Value: 2147483647
Minimum Value: 1
Type: number
SQL_Sybase_OpenServer_Exec
pam.sql.sybase.exec.limit
Default Value: 6
Maximum Value: 65535
Minimum Value: 0
Type: number
SSH_Banner_Length
pam.ssh.maxBannerLen
Default Value: 255
Maximum Value: 4294967295
Minimum Value: 1
Type: number
SSH_Brute_Force
pam.login.ssh.count
Default Value: 12
Maximum Value: 409
Minimum Value: 1
Type: number
pam.login.ssh.interval
Default Value: 60
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.login.ssh.short.session.time
Default Value: 5
Maximum Value: 300
Minimum Value: 2
Type: number
SSH_ChallengeResponse_Bo
pam.ssh.search.threshold
Default Value: 48
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.ssh.search.charcount
Default Value: 32768
Maximum Value: 4294967295
Minimum Value: 1
Type: number
SSH_Service_Sweep
pam.tcp.sweep.syn
Default Value: false
Type: Boolean
SSL2_Master_Key_Overflow
pam.ssl.v2masterkey.arglenthreshold
Default Value: 8
Maximum Value: 2147483647
Minimum Value: 1
Type: number
SSL_Challenge_Length_Overflow
pam.sslv2.client-hello.challenge-length
Default Value: 32
Maximum Value: 4294967295
Minimum Value: 32
Type: number
SSL_V2_MySQL_Hello_Overflow
pam.sslv2.mysql.max.ciphers.length
Default Value: 96
Maximum Value: 4294967295
Minimum Value: 0
Type: number
SSL_V2_OpenSSL_Get_Shared_Ciphers_BO
pam.ssl.maxciphers
Default Value: 80
Maximum Value: 4294967295
Minimum Value: 0
Type: number
SSL_V3_MySQL_Hello_Overflow
pam.sslv3.mysql.max.ciphers.length
Default Value: 64
Maximum Value: 4294967295
Minimum Value: 0
Type: number
SSL_V3_OpenSSL_Get_Shared_Ciphers_BO
pam.ssl.maxciphers
Default Value: 80
Maximum Value: 4294967295
Minimum Value: 0
Type: number
STUN_KPhone_DoS
pam.stun.kphone.dos.detect
Default Value: false
Type: Boolean
SYNFlood
pam.tcp.synflood.update
Default Value: 180
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.tcp.synflood.limit
Default Value: 1000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.tcp.synflood.custom.limit
Default Value: 5000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.tcp.synflood.dstport
Default Value: true
Type: Boolean
pam.tcp.synflood.window
Default Value: 60
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.tcp.synflood.size
Default Value: 65528
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.tcp.synflood.custom
Type: string
SYNFlood_Protection
pam.tcp.synflood.update
Default Value: 180
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.tcp.synflood.protection.duplicatesyn.timeout
Default Value: 6
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
pam.tcp.synflood.protection.untrusted.rate
Default Value: 10
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.tcp.synflood.protection.duplicatesyn.enabled
Default Value: true
Type: Boolean
pam.tcp.synflood.limit
Default Value: 1000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.tcp.synflood.protection.duplicatesyn.retransmit
Default Value: 2
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
pam.tcp.synflood.custom.limit
Default Value: 5000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.tcp.synflood.dstport
Default Value: true
Type: Boolean
pam.tcp.synflood.window
Default Value: 60
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.tcp.synflood.size
Default Value: 65528
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.tcp.synflood.custom
Type: string
SYN_Bandwidth_Flood
pam.tcp.synflood.update
Default Value: 180
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.tcp.synflood.bandwidth.limit
Default Value: 15000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.tcp.synflood.dstport
Default Value: true
Type: Boolean
pam.tcp.synflood.window
Default Value: 60
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.tcp.synflood.size
Default Value: 65528
Maximum Value: 4294967295
Minimum Value: 0
Type: number
SYN_Bandwidth_Flood_Protection
pam.tcp.synflood.update
Default Value: 180
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.tcp.synflood.protection.duplicatesyn.timeout
Default Value: 6
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
pam.tcp.synflood.protection.untrusted.rate
Default Value: 10
Maximum Value: 4294967295
Minimum Value: 0
Type: number
pam.tcp.synflood.protection.duplicatesyn.enabled
Default Value: true
Type: Boolean
pam.tcp.synflood.protection.duplicatesyn.retransmit
Default Value: 2
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
pam.tcp.synflood.bandwidth.limit
Default Value: 15000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.tcp.synflood.dstport
Default Value: true
Type: Boolean
pam.tcp.synflood.window
Default Value: 60
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.tcp.synflood.size
Default Value: 65528
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Script_Concealed_Content
pam.script.concealed.content.http
Default Value: false
Type: Boolean
Script_Exploit_Fingerprint
pam.fingerprint.token.enabled
Default Value: true
Type: Boolean
Script_IE_IsComponentInstalled_BO
pam.http.ie.iscomponentinstalled.limit
Default Value: 450
Maximum Value: 16535
Minimum Value: 1
Type: number
Script_Suspicious_Score
pam.script.suspicious.score.limit
Default Value: 100
Maximum Value: 10000
Minimum Value: -1000
Type: number
Security_Management_Heap_BO
pam.udp.secmgmt.allports
Default Value: false
Type: Boolean
pam.udp.secmgmt.altport
Default Value: 0
Maximum Value: 65535
Minimum Value: 0
Type: number
Security_Management_Integer_Underflow
pam.udp.secmgmt.allports
Default Value: false
Type: Boolean
pam.udp.secmgmt.altport
Default Value: 0
Maximum Value: 65535
Minimum Value: 0
Type: number
Security_Management_StringSize_Overflow
pam.udp.secmgmt.allports
Default Value: false
Type: Boolean
pam.udp.secmgmt.altport
Default Value: 0
Maximum Value: 65535
Minimum Value: 0
Type: number
SensorStatistics
pam.statistics.interval
Default Value: 300
Maximum Value: 2592000
Minimum Value: 1
Type: number
Units: seconds
pam.statistics
Default Value: true
Type: Boolean
pam.statistics.samplewindow
Default Value: 1000000
Maximum Value: 6000000
Minimum Value: 1000
Type: number
Units: micro-seconds
SensorStatistics_Cumulative
pam.statistics.interval
Default Value: 300
Maximum Value: 2592000
Minimum Value: 1
Type: number
Units: seconds
pam.statistics
Default Value: true
Type: Boolean
pam.statistics.samplewindow
Default Value: 1000000
Maximum Value: 6000000
Minimum Value: 1000
Type: number
Units: micro-seconds
SensorStatistics_MicroCumulative
pam.statistics.micro.interval
Default Value: 0
Maximum Value: 4294967295
Minimum Value: 300
Type: number
Units: seconds
Shell_Command_Injection
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.shell.pedantic
Default Value: true
Type: Boolean
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.injection.argument.token.limit
Default Value: 8
Maximum Value: 100
Minimum Value: 0
Type: number
pam.injection.shell.score
Default Value: 4
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
Skype_Detected
pam.skype.netmask
Default Value: 255.255.0.0
Type: IP Address
Socks_Auth_Failed
pam.login.socks.interval
Default Value: 3600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.login.socks.count
Default Value: 4
Maximum Value: 409
Minimum Value: 1
Type: number
Stream_DoS
pam.flood.ack.interval
Default Value: 2
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.flood.ack.limit
Default Value: 3000
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.flood.ack.size
Default Value: 2048
Maximum Value: 1048576
Minimum Value: 1
Type: number
pam.flood.ack.multiplier
Default Value: 10
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Subversion_Date_Parsing_BO
pam.subversion.getdatedrev.limit
Default Value: 64
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
Sunrpc_rwall_Message_Overflow
pam.rpc.rwall.msglen
Default Value: 512
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Swf_Video_Stream_Detected
pam.flash.compressed.parse
Default Value: true
Type: Boolean
Syslog_Flood
pam.syslog.flood.interval
Default Value: 2
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.syslog.flood.count
Default Value: 1500
Maximum Value: 2000
Minimum Value: 1
Type: number
TCP_Connections_Open_Flood
pam.tcp.connections.flood.custom.opened
Default Value: 480
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.tcp.connections.flood.opened
Default Value: 160
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.tcp.connections.flood.custom
Type: string
pam.tcp.connections.flood.window
Default Value: 60
Maximum Value: 4294967295
Minimum Value: 1
Type: number
TCP_Connections_Rate_Flood
pam.tcp.connections.flood.custom.rate
Default Value: 1800
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.tcp.connections.flood.custom
Type: string
pam.tcp.connections.flood.rate
Default Value: 600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.tcp.connections.flood.window
Default Value: 60
Maximum Value: 4294967295
Minimum Value: 1
Type: number
TCP_Dabber_Sweep
pam.tcp.sweep.syn
Default Value: false
Type: Boolean
TCP_Dataless_Session_RST_DoS
pam.flood.rst.size
Default Value: 16
Maximum Value: 1048576
Minimum Value: 1
Type: number
pam.flood.rst.limit
Default Value: 300
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.flood.rst.interval
Default Value: 30
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.flood.rst.multiplier
Default Value: 10
Maximum Value: 4294967295
Minimum Value: 1
Type: number
TCP_Orphaned_Sessions_DoS
pam.tcp.orphaned.sessions.count
Default Value: 20
Maximum Value: 1000
Minimum Value: 1
Type: number
pam.tcp.orphaned.sessions.interval
Default Value: 600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
TCP_Service_Sweep
pam.tcp.sweep.syn
Default Value: false
Type: Boolean
TCP_Small_Window_DoS
pam.tcp.smallwindow.probes
Default Value: 100
Maximum Value: 2147483647
Minimum Value: 1
Type: number
pam.tcp.smallwindow.secs
Default Value: 5
Maximum Value: 2147483647
Minimum Value: 0
Type: number
pam.tcp.smallwindow.size
Default Value: 32
Maximum Value: 4294967295
Minimum Value: 1
Type: number
TCP_SynAck_With_Data
pam.tcp.syndata.size
Default Value: 50
Maximum Value: 2000
Minimum Value: 1
Type: number
TCP_Syn_With_Data
pam.tcp.syndata.size
Default Value: 50
Maximum Value: 2000
Minimum Value: 1
Type: number
TCP_Timestamp_DoS
pam.tcp.timestamp.delta
Default Value: 100000
Maximum Value: 500000000
Minimum Value: 1
Type: number
TCP_Within_Window_DoS
pam.tcp.outside.window.exact.rst.max
Default Value: 3
Maximum Value: 60000
Minimum Value: 0
Type: number
pam.tcp.outside.window.max
Default Value: 24
Maximum Value: 60000
Minimum Value: 0
Type: number
TCP_Zero_Window_DoS
pam.tcp.zerowindow.probes
Default Value: 100
Maximum Value: 2147483647
Minimum Value: 25
Type: number
TFTP_File_Brute_Force
pam.file.tftp.interval
Default Value: 20
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.file.tftp.count
Default Value: 10
Maximum Value: 409
Minimum Value: 1
Type: number
TFTP_Filename_VeryLong
pam.file.maxname
Default Value: 150
Maximum Value: 2147483647
Minimum Value: 1
Type: number
TFTP_Long_Transfer_Mode
pam.tftp.mode.limit
Default Value: 16
Maximum Value: 4294967295
Minimum Value: 4
Type: number
TLS_Connections_Rate_Flood
pam.tls.connections.flood.custom.rate
Default Value: 150
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.tls.connections.flood.rate
Default Value: 120
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.tcp.connections.flood.window
Default Value: 60
Maximum Value: 4294967295
Minimum Value: 1
Type: number
TLS_Excessive_Renegotiations
pam.tls.renegotiation.client-only
Default Value: false
Type: Boolean
pam.tls.renegotiation.threshold
Default Value: 5
Maximum Value: 65535
Minimum Value: 1
Type: number
pam.tls.renegotiation.interval
Default Value: 60
Maximum Value: 65535
Minimum Value: 5
Type: number
TLS_Large_Client_Certificate
pam.tls.long.certificate.length
Default Value: 3072
Maximum Value: 65535
Minimum Value: 0
Type: number
TLS_Weak_Cipher_Suite
pam.tls.strong.cipher.length
Default Value: 112
Maximum Value: 65535
Minimum Value: 0
Type: number
TLS_Weak_X509_Certificate
pam.tls.strong.certificate.length
Default Value: 1024
Maximum Value: 65535
Minimum Value: 0
Type: number
TLS_Zero_Length_Record
pam.tls.allow.zerolen.appdata
Default Value: true
Type: Boolean
Telnet_Auth_Failed
pam.login.telnet.count
Default Value: 4
Maximum Value: 409
Minimum Value: 1
Type: number
pam.login.telnet.interval
Default Value: 3600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
Telnet_Inline_Demo_Capslock
pam.telnet.rewrite
Default Value: false
Type: Boolean
Telnet_Login_Overflow
pam.login.maxname
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Telnet_Password_Overflow
pam.login.maxpass
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Telnet_PolycomDoS
pam.telnet.polycomdos.count
Default Value: 75
Maximum Value: 409
Minimum Value: 1
Type: number
pam.telnet.polycomdos.interval
Default Value: 60
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Timbuktu_Login_Overflow
pam.timbuktu.max.username.length
Default Value: 31
Maximum Value: 65535
Minimum Value: 1
Type: number
Trace_Route
pam.icmp.traceroute.interval
Default Value: 10
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.icmp.traceroute.count
Default Value: 2
Maximum Value: 2000
Minimum Value: 1
Type: number
Trace_Route_UDP
pam.icmp.traceroute.interval
Default Value: 10
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.icmp.traceroute.count
Default Value: 2
Maximum Value: 2000
Minimum Value: 1
Type: number
Twinge_Attack
pam.flood.icmp.limit
Aliases: pam.icmp.maxcnt
Default Value: 100
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.flood.icmp.size
Default Value: 512
Maximum Value: 1048576
Minimum Value: 1
Type: number
pam.flood.icmp.interval
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
UDP_Flood_DoS
pam.flood.udp.size
Default Value: 2048
Maximum Value: 1048576
Minimum Value: 1
Type: number
pam.flood.udp.limit
Default Value: 15
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.flood.udp.port.whitelist
Maximum Value: 65535
Minimum Value: 0
Type: number
pam.flood.udp.interval
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.flood.udp.protection
Default Value: false
Type: Boolean
pam.flood.udp.timeout
Default Value: 60
Maximum Value: 65535
Minimum Value: 2
Type: number
UDP_Squid_WCCP_Overflow
pam.wccp.packet.threshold
Default Value: 1428
Maximum Value: 32767
Minimum Value: 24
Type: number
UDP_Storm_Worm
pam.udp.stormworm.count
Default Value: 120
Maximum Value: 409
Minimum Value: 1
Type: number
pam.udp.stormworm.interval
Default Value: 60
Maximum Value: 4294967295
Minimum Value: 1
Type: number
UDP_Syslogd_BO
pam.udp.syslog.threshold
Default Value: 1024
Maximum Value: 2147483647
Minimum Value: 0
Type: number
URL_File_URI_Overflow
pam.parser.urlfile.enabled
Default Value: true
Type: Boolean
pam.urlfile.scan.limit
Default Value: 128
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
pam.urlfile.uri.limit
Default Value: 512
Maximum Value: 2147483647
Minimum Value: -2147483648
Type: number
Ultravox_Winamp_MP3_BO
pam.ultravox.winamp.mp3tags.limit
Default Value: 4077
Maximum Value: 65535
Minimum Value: 256
Type: number
Unicenter_Msg_Queue_BO
pam.unicenter.msgqbo.limit
Default Value: 256
Maximum Value: 32766
Minimum Value: 0
Type: number
Unistim_Audio_Hijack
pam.unistim.audio.hijack.interval
Default Value: 4
Maximum Value: 65535
Minimum Value: 1
Type: number
pam.unistim.audio.hijack.packets
Default Value: 5
Maximum Value: 65535
Minimum Value: 1
Type: number
Unistim_Flood
pam.flood.unistim.interval
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.flood.unistim.limit
Default Value: 250
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.flood.unistim.size
Default Value: 4
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.flood.unistim.multiplier
Default Value: 2
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Unistim_Reregister_DoS
pam.unistim.reset.limit
Default Value: 3
Maximum Value: 65535
Minimum Value: 1
Type: number
VNC_HTTP_Get_Overflow
pam.http.url.vnc
Default Value: 1024
Maximum Value: 65535
Minimum Value: 1
Type: number
VNC_Login_Failed_User
pam.login.vnc.interval
Default Value: 3600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.login.vnc.count
Default Value: 4
Maximum Value: 409
Minimum Value: 1
Type: number
VOIP_Brute_Force
pam.voip.bruteforce.interval
Default Value: 3
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.voip.bruteforce.count
Default Value: 50
Maximum Value: 409
Minimum Value: 1
Type: number
VOIP_DRDoS
pam.voip.drdos.interval
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.voip.drdos.count
Default Value: 25
Maximum Value: 409
Minimum Value: 1
Type: number
VOIP_New_Call_Dos
pam.flood.newcalldos.size
Default Value: 4
Maximum Value: 1048576
Minimum Value: 1
Type: number
pam.flood.newcalldos.multiplier
Default Value: 2
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.flood.newcalldos.limit
Default Value: 250
Maximum Value: 4294967295
Minimum Value: 1
Type: number
pam.flood.newcalldos.interval
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
VRRP_Detected
pam.vrrp.report.limit
Default Value: 600
Maximum Value: 2147483647
Minimum Value: 1
Type: number
Veritas_BackupExec_BO
pam.veritas.hostname.limit
Default Value: 66
Maximum Value: 65535
Minimum Value: 1
Type: number
Veritas_NetBackup_ConnectOptions_Overflow
pam.veritas.hostname.limit
Default Value: 66
Maximum Value: 65535
Minimum Value: 1
Type: number
Veritas_NetBackup_Request_Overflow
pam.veritas.bpcd.request.limit
Default Value: 0x8000
Maximum Value: 65535
Minimum Value: 1
Type: number
WINS_PointerHijack
pam.wins.pdu.length.limit
Default Value: 4096
Maximum Value: 4294967295
Minimum Value: 1
Type: number
WINS_UDP_Pointer_Code_Exec
pam.WINS_UDP_Pointer_Code_Exec.limit
Default Value: 50
Maximum Value: 4294967295
Minimum Value: 0
Type: number
WinAmp_Playlist_Long_Filename_Overflow
pam.pls.binaryonly
Default Value: true
Type: Boolean
pam.pls.urlsize
Default Value: 1024
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Win_MessengerPopup_Bo
pam.win.messengerpopup.limit
Default Value: 2200
Maximum Value: 1000000
Minimum Value: 0
Type: number
Windows_NNTP_Overflow
pam.nntp.xpat.line.limit
Default Value: 200
Maximum Value: 4294967295
Minimum Value: 0
Type: number
Windows_Printing_Service_DOS
pam.lpr.dos.interval
Default Value: 1
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.lpr.dos.count
Default Value: 10
Maximum Value: 2000
Minimum Value: 1
Type: number
WordPro_Shellcode_Detected
pam.wordpro.scan.limit
Default Value: 40000
Maximum Value: 4294967295
Minimum Value: 0
Type: number
XML_Document_Too_Large
pam.content.xml.limit
Default Value: 8388608
Maximum Value: 4294967295
Minimum Value: 0
Type: number
XML_EntityDecl_DoS
pam.content.xml.entitydecl.limit
Default Value: 50
Maximum Value: 4294967295
Minimum Value: 0
Type: number
XML_EntityRef_DoS
pam.content.xml.entityref.limit
Default Value: 10000
Maximum Value: 4294967295
Minimum Value: 0
Type: number
XML_Entity_Name_Overflow
pam.content.xml.entityname.limit
Default Value: 200
Maximum Value: 4294967295
Minimum Value: 0
Type: number
XML_JNLP_Codebase_BO
pam.content.jnlp.codebase.max
Default Value: 1024
Maximum Value: 4294967295
Minimum Value: 0
Type: number
XML_LibreOffice_Manifest_Malformed
pam.content.zip.decompress
Default Value: false
Type: Boolean
XML_Libxml2_DTD_Element_DoS
pam.content.xml.element.depth.limit
Default Value: 256
Maximum Value: 4294967295
Minimum Value: 0
Type: number
XML_Name_Overflow
pam.content.xml.name.limit
Default Value: 255
Maximum Value: 65536
Minimum Value: 0
Type: number
XML_QuickTime_QTL_Long_Type
pam.content.qtl.type.limit
Default Value: 127
Maximum Value: 65535
Minimum Value: 0
Type: number
XML_Word_Access_Violation
pam.content.zip.decompress
Default Value: false
Type: Boolean
XPATH_Injection
pam.injection.facebook_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.sql.boolean.triggers
Default Value: 1
Maximum Value: 2
Minimum Value: 0
Type: number
pam.injection.yahoo_fingerprint.enable
Default Value: true
Type: Boolean
pam.injection.http.headers.enabled
Default Value: true
Type: Boolean
pam.parser.argument.injection.enabled
Default Value: true
Type: Boolean
pam.injection.http.hostpath.enabled
Default Value: true
Type: Boolean
YahooMSG_Filename_Overflow
pam.yahoo.filename.limit
Default Value: 124
Maximum Value: 4294967295
Minimum Value: 1
Type: number
YahooMSG_UserID_Overflow
pam.yahoo.userid.limit
Default Value: 32
Maximum Value: 4294967295
Minimum Value: 1
Type: number
ZenWorks_remMgr_Overflow
pam.parser.zenWorks.remMgr.maxLength
Default Value: 0xff
Maximum Value: 65535
Minimum Value: 0
Type: number
pcAnywhere_Login_Failed
pam.login.pcanywhere.interval
Default Value: 3600
Maximum Value: 4294967295
Minimum Value: 1
Type: number
Units: seconds
pam.login.pcanywhere.count
Default Value: 4
Maximum Value: 409
Minimum Value: 1
Type: number
Wednesday, 16 January 2013
Wednesday, 18 July 2012
802.1X Remote desktop (RDP) user authentication
When connecting through remote desktop (RDP) to machines that are connected to 802.1X enabled switch ports (for example in Cisco ISE installations), connectivity issues, and session failures and disconnection issues could happen.
Most of these issues are related to the fact that native 802.1X supplicants don't authenticate and authorize users that connect through RDP. Access lists on port are left as you have machine with no user logged on it. In most cases these ACLs allow only traffic for logging user on domain etc., and remote desktop traffic is not allowed by these ACLs.
We have resolved this issue by using Cisco AnyConnect Secure Mobility Client with Network Access Manager - NAM module, as it behaves better and eliminates this problem by authenticating and authorizing user that is connecting through RDP and granting all rights and expected ACLs.
Labels:
802.1X,
Cisco,
IOS,
ISE,
Microsoft,
Remote desktop,
security,
switches,
troubleshooting,
Windows 7
Cisco ISE - duplicate IP address on Windows 7
Windows 7 sometimes reports IP address conflict (duplicate IP address warning message) when connected to 802.1X enabled ports while device tracking feature is used on switch. Device tracking is used in most Cisco ISE designs. You can check if you have device tracking on switch with:
Solution 1 - Delay ip device tracking ARP probe for few seconds (you should have IOS version that supports this command).
Solution 2 - Disable gratuitous ARP in Windows registry [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters] Set ArpRetryCount (32-bit DWORD) to 0 If you decide to use second method, please be sure to manage duplicate address problem with some other controls on switches or elsewhere.
With device tracking probe delay we had really good results, and believe there is no need for registry tuning (and problem with it is that when new machine with default registry settings is connected, you will again get same duplicate IP address problem).
switch#sh run | inc trackin ip device tracking switch#This usually happens on Windows Vista, Windows 2008 and Windows 7 clients, when disconnecting and connecting again (or shut no shut on switch), after locking and unlocking, or logging off and then logging on. Reason behind this is that windows machines could send ARP packets at the same time the switch is probing for device status. Possible solutions are:
Solution 1 - Delay ip device tracking ARP probe for few seconds (you should have IOS version that supports this command).
Switch(config)# ip device tracking [probe {delay interval}]
ARP packet will be sent few seconds after link-up, and it will not happen at same time when windows 7 clients send first ARP packets.
For example:
switch(config)#ip device tracking probe delay 5
Solution 2 - Disable gratuitous ARP in Windows registry [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters] Set ArpRetryCount (32-bit DWORD) to 0 If you decide to use second method, please be sure to manage duplicate address problem with some other controls on switches or elsewhere.
With device tracking probe delay we had really good results, and believe there is no need for registry tuning (and problem with it is that when new machine with default registry settings is connected, you will again get same duplicate IP address problem).
Monday, 5 December 2011
VRF aware IPSEC with NAT using only one WAN (outside) interface
If you need to terminate all customers (or users, or any other remote parties) on only one WAN (outside) interface, for example when terminating IPSec VPN on Internet facing interface, method described in our previous post - VRF aware IPSEC with NAT, although quite useful and flexible, can't be used.
But with few changes it is possible. In configuration below a single crypto map with two entries is applied on WAN (outside facing) interface, so subinterfaces are no longer needed.
Although not directly related to this concept, additional NAT rule for translating inside LAN address on central site is also added. But this part is also quite useful, since it shows statefullness of new NAT feature. It is possible to reach central site from customers sites using both real, and natted addresses. If packets to real address are sent from customer sites, return traffic will keep real address (ip nat source static 10.10.2.1 192.168.192.1 vrf Central_VRF will not be used). If NATed address is used, NAT will of course do its job. So there is different behavior for same packet coming from central LAN towards customer sites, depending part of which session it is (it depends did the customer sent a packet to real or natted IP address).
Special care needs to be made with VRFs in many commands below. With any small misconfiguration it will not work.
Central site router:
But with few changes it is possible. In configuration below a single crypto map with two entries is applied on WAN (outside facing) interface, so subinterfaces are no longer needed.
Although not directly related to this concept, additional NAT rule for translating inside LAN address on central site is also added. But this part is also quite useful, since it shows statefullness of new NAT feature. It is possible to reach central site from customers sites using both real, and natted addresses. If packets to real address are sent from customer sites, return traffic will keep real address (ip nat source static 10.10.2.1 192.168.192.1 vrf Central_VRF will not be used). If NATed address is used, NAT will of course do its job. So there is different behavior for same packet coming from central LAN towards customer sites, depending part of which session it is (it depends did the customer sent a packet to real or natted IP address).
Special care needs to be made with VRFs in many commands below. With any small misconfiguration it will not work.
Central site router:
ip vrf Central_VRF
rd 100:100
!
ip vrf Customer_A_VRF
rd 100:101
!
ip vrf Customer_B_VRF
rd 100:102
!
ip vrf WAN
rd 100:99
!
crypto keyring Customer_A_CRYPTO_KEYRING vrf WAN
pre-shared-key address 192.168.1.11 key abc123
crypto keyring Customer_B_CRYPTO_KEYRING vrf WAN
pre-shared-key address 192.168.1.12 key abc123
!
crypto isakmp policy 10
encr aes 256
authentication pre-share
group 2
crypto isakmp profile Customer_A_ISAKMP_PROFILE
vrf Customer_A_VRF
keyring Customer_A_CRYPTO_KEYRING
match identity address 192.168.1.11 255.255.255.255 WAN
crypto isakmp profile Customer_B_ISAKMP_PROFILE
vrf Customer_B_VRF
keyring Customer_B_CRYPTO_KEYRING
match identity address 192.168.1.12 255.255.255.255 WAN
!
crypto ipsec transform-set Customer_A_TRANSFORM_SET esp-aes 256 esp-sha-hmac
crypto ipsec transform-set Customer_B_TRANSFORM_SET esp-aes 256 esp-sha-hmac
!
crypto map WAN_CRYPTO_MAP 10 ipsec-isakmp
set peer 192.168.1.11
set transform-set Customer_A_TRANSFORM_SET
set isakmp-profile Customer_A_ISAKMP_PROFILE
match address Customer_A_CRYPTO_ACL
crypto map WAN_CRYPTO_MAP 20 ipsec-isakmp
set peer 192.168.1.12
set transform-set Customer_B_TRANSFORM_SET
set isakmp-profile Customer_B_ISAKMP_PROFILE
match address Customer_B_CRYPTO_ACL
!
interface GigabitEthernet0/1
description WAN
ip vrf forwarding WAN
ip address 192.168.1.2 255.255.255.240
ip nat enable
no ip route-cache cef
no ip route-cache
duplex auto
speed auto
crypto map WAN_CRYPTO_MAP
!
interface GigabitEthernet0/2
description To_Central_LAN
ip vrf forwarding Central_VRF
ip address 10.10.1.1 255.255.255.0
ip nat enable
no ip route-cache cef
no ip route-cache
duplex auto
speed auto
!
ip nat source static 10.10.2.1 192.168.192.1 vrf Central_VRF
ip nat source static 192.168.10.1 10.10.101.1 vrf Customer_A_VRF
ip nat source static 192.168.10.1 10.10.102.1 vrf Customer_B_VRF
ip route vrf Central_VRF 192.168.192.1 255.255.255.255 10.10.1.2
ip route vrf Central_VRF 10.10.2.1 255.255.255.255 10.10.1.2
ip route vrf Central_VRF 10.10.101.1 255.255.255.255 GigabitEthernet0/1 192.168.1.11
ip route vrf Central_VRF 10.10.102.1 255.255.255.255 GigabitEthernet0/1 192.168.1.12
ip route vrf Customer_A_VRF 192.168.10.1 255.255.255.255 GigabitEthernet0/1 192.168.1.11
ip route vrf Customer_A_VRF 192.168.192.1 255.255.255.255 GigabitEthernet0/2 10.10.1.2
ip route vrf Customer_A_VRF 10.10.2.1 255.255.255.255 GigabitEthernet0/2 10.10.1.2
ip route vrf Customer_B_VRF 192.168.10.1 255.255.255.255 GigabitEthernet0/1 192.168.1.12
ip route vrf Customer_B_VRF 192.168.192.1 255.255.255.255 GigabitEthernet0/2 10.10.1.2
ip route vrf Customer_B_VRF 10.10.2.1 255.255.255.255 GigabitEthernet0/2 10.10.1.2
!
ip access-list extended Customer_A_CRYPTO_ACL
permit ip 10.10.2.0 0.0.0.255 192.168.10.0 0.0.0.255
permit ip 192.168.192.0 0.0.0.255 192.168.10.0 0.0.0.255
ip access-list extended Customer_B_CRYPTO_ACL
permit ip 10.10.2.0 0.0.0.255 192.168.10.0 0.0.0.255
permit ip 192.168.192.0 0.0.0.255 192.168.10.0 0.0.0.255
Friday, 18 November 2011
VRF aware IPSEC with NAT
(If you need to terminate all customers (or users, or any other remote parties) on only one WAN (outside) interface, for example when terminating IPSec VPN on Internet facing interface, see also VRF aware IPSEC with NAT using only one WAN (outside) interface)
If it is required to terminate multiple IPsec connections from multiple customers on same router, and customer address spaces are overlapping, one solution is VRF aware IPsec together with VRF aware NAT functionality using new ip nat enable syntax.
Each customer is connected to central site using its own private link that is through 802.1q connected to separate subinterface dedicated to each customer on WAN interface on central router.
In this example both customer sites arrive to central site using same IP address from their LAN: 192.168.10.1
This IP address is NAT-ed to 10.10.101.1 for customer A, and to 10.10.102.1 for customer B.
This allows central site to differentiate packets sent from different customers with same source IP address, and to be able to correctly route packets back.
There are numerous parts in this setup to do wrong. Some of the possible errors are:
proxy identities not supported
IPSec policy invalidated proposal with error 32
phase 2 SA policy not acceptable
peer matches *none* of the profiles
Central site router:
If it is required to terminate multiple IPsec connections from multiple customers on same router, and customer address spaces are overlapping, one solution is VRF aware IPsec together with VRF aware NAT functionality using new ip nat enable syntax.
Each customer is connected to central site using its own private link that is through 802.1q connected to separate subinterface dedicated to each customer on WAN interface on central router.
In this example both customer sites arrive to central site using same IP address from their LAN: 192.168.10.1
This IP address is NAT-ed to 10.10.101.1 for customer A, and to 10.10.102.1 for customer B.
This allows central site to differentiate packets sent from different customers with same source IP address, and to be able to correctly route packets back.
There are numerous parts in this setup to do wrong. Some of the possible errors are:
proxy identities not supported
IPSec policy invalidated proposal with error 32
phase 2 SA policy not acceptable
Jun 17 13:24:57.739: IPSEC(ipsec_process_proposal): proxy identities not supportedProfile discarded due to VRF mismatch
Jun 17 13:24:57.739: ISAKMP:(1009): IPSec policy invalidated proposal with error 32
Jun 17 13:24:57.739: ISAKMP:(1009): phase 2 SA policy not acceptable! (local 192.168.1.2 remote 192.168.1.1)
peer matches *none* of the profiles
Jun 18 09:24:55.763: ISAKMP:(0):: Profile User_A_ISAKMP_PROFILE discarded due to VRF mismatch * * *unroutable in debug ip packet output
Jun 18 09:24:55.763: ISAKMP:(0):: Have you put proper FVRF in "match id ip-address" command?
Jun 18 09:24:55.763: ISAKMP:(0):: peer matches *none* of the profiles
Jun 18 13:03:31.107: IP: s=192.168.10.1 (GigabitEthernet0/1.102), d=10.10.2.1, len 100, unroutableImportant parts to make this all working are (bold in Central site router configuration below):
- Add vrf vrf name after crypto keyring commands.
- Add vrf name after match identity address in crypto isakmp profiles.
- Put frontend outside interfaces in FVRF using ip vrf forwarding commands.
- We have found 15.0-1.M7 to be more stable with this setup, but in the meantime it is possible that newer releases in 15.1 and 15.2 are also fine
- Use two routes for each customer, one in Central VRF (with addresses NAT-ed to addresses how customer addresses are seen on Central site, one in Customer VRF (with original non-NAT-ed customer addresses - since we are using VRFs and NAT, these addresses can (and in this example are) overlapping.
ip route vrf Central_site_VRF 10.10.101.1 255.255.255.255 GigabitEthernet0/1.101 192.168.1.1Here are working configurations:
ip route vrf Central_site_VRF 10.10.102.1 255.255.255.255 GigabitEthernet0/1.102 192.168.1.1
ip route vrf Customer_A_VRF 192.168.10.1 255.255.255.255 GigabitEthernet0/1.101 192.168.1.1
ip route vrf Customer_B_VRF 192.168.10.1 255.255.255.255 GigabitEthernet0/1.102 192.168.1.1
Central site router:
ip vrf Central_site_VRFCustomer A:
rd 100:100
!
ip vrf Customer_A_VRF
rd 100:101
!
ip vrf Customer_B_VRF
rd 100:102
!
crypto keyring Customer_A_CRYPTO_KEYRING vrf Customer_A_VRF
pre-shared-key address 192.168.1.1 key abc123
crypto keyring Customer_B_CRYPTO_KEYRING vrf Customer_B_VRF
pre-shared-key address 192.168.1.1 key abc123
!
crypto isakmp policy 10
encr aes 256
authentication pre-share
group 2
crypto isakmp profile Customer_A_ISAKMP_PROFILE
vrf Customer_A_VRF
keyring Customer_A_CRYPTO_KEYRING
match identity address 192.168.1.1 255.255.255.255 Customer_A_VRF
crypto isakmp profile Customer_B_ISAKMP_PROFILE
vrf Customer_B_VRF
keyring Customer_B_CRYPTO_KEYRING
match identity address 192.168.1.1 255.255.255.255 Customer_B_VRF
!
crypto ipsec transform-set Customer_A_TRANSFORM_SET esp-aes 256 esp-sha-hmac
crypto ipsec transform-set Customer_B_TRANSFORM_SET esp-aes 256 esp-sha-hmac
!
crypto map Customer_A_CRYPTO_MAP 10 ipsec-isakmp
set peer 192.168.1.1
set transform-set Customer_A_TRANSFORM_SET
set isakmp-profile Customer_A_ISAKMP_PROFILE
match address Customer_A_CRYPTO_ACL
!
crypto map Customer_B_CRYPTO_MAP 10 ipsec-isakmp
set peer 192.168.1.1
set transform-set Customer_B_TRANSFORM_SET
set isakmp-profile Customer_B_ISAKMP_PROFILE
match address Customer_B_CRYPTO_ACL
!
interface GigabitEthernet0/0
no ip address
shutdown
duplex auto
speed auto
!
interface GigabitEthernet0/1
description WAN Interface
no ip address
duplex auto
speed auto
!
!
interface GigabitEthernet0/1.101
description To_Customer_A
encapsulation dot1Q 101
ip vrf forwarding Customer_A_VRF
ip address 192.168.1.2 255.255.255.0
ip nat enable
crypto map Customer_A_CRYPTO_MAP
!
interface GigabitEthernet0/1.102
description To_Customer_B
encapsulation dot1Q 102
ip vrf forwarding Customer_B_VRF
ip address 192.168.1.2 255.255.255.0
ip nat enable
crypto map Customer_B_CRYPTO_MAP
!
interface GigabitEthernet0/2
description To_Central_site_LAN
ip vrf forwarding Central_site_VRF
ip address 10.10.1.1 255.255.255.0
ip nat enable
duplex auto
speed auto
!
ip forward-protocol nd
!
ip nat source static 192.168.10.1 10.10.101.1 vrf Customer_A_VRF
ip nat source static 192.168.10.1 10.10.102.1 vrf Customer_B_VRF
ip route vrf Central_site_VRF 10.10.2.1 255.255.255.255 10.10.1.2
ip route vrf Central_site_VRF 10.10.101.1 255.255.255.255 GigabitEthernet0/1.101 192.168.1.1
ip route vrf Central_site_VRF 10.10.102.1 255.255.255.255 GigabitEthernet0/1.102 192.168.1.1
ip route vrf Customer_A_VRF 10.10.2.1 255.255.255.255 GigabitEthernet0/2 10.10.1.2
ip route vrf Customer_A_VRF 192.168.10.1 255.255.255.255 GigabitEthernet0/1.101 192.168.1.1
ip route vrf Customer_B_VRF 10.10.2.1 255.255.255.255 GigabitEthernet0/2 10.10.1.2
ip route vrf Customer_B_VRF 192.168.10.1 255.255.255.255 GigabitEthernet0/1.102 192.168.1.1
!
ip access-list extended Customer_A_CRYPTO_ACL
permit ip 10.10.2.0 0.0.0.255 192.168.10.0 0.0.0.255
ip access-list extended Customer_B_CRYPTO_ACL
permit ip 10.10.2.0 0.0.0.255 192.168.10.0 0.0.0.255
crypto isakmp policy 10Customer B (same as Customer B - to cover overlapping addresses case. It is of course possible to have different configurations, even different router or firewall vendors at customer sites):
encr aes 256
authentication pre-share
group 2
crypto isakmp key abc123 address 0.0.0.0 0.0.0.0
!
crypto ipsec transform-set ts esp-aes 256 esp-sha-hmac
!
crypto map CRYPTO_MAP 10 ipsec-isakmp
set peer 192.168.1.2
set transform-set ts
match address CRYPTO_ACL
!
interface Loopback0
ip address 192.168.10.1 255.255.255.255
!
interface FastEthernet0/0
ip address 192.168.1.1 255.255.255.252
speed auto
crypto map CRYPTO_MAP
!
ip route 0.0.0.0 0.0.0.0 192.168.1.2
!
ip access-list extended CRYPTO_ACL
permit ip 192.168.10.0 0.0.0.255 10.10.2.0 0.0.0.255
crypto isakmp policy 10
encr aes 256
authentication pre-share
group 2
crypto isakmp key abc123 address 0.0.0.0 0.0.0.0
!
!
crypto ipsec transform-set ts esp-aes 256 esp-sha-hmac
!
crypto map CRYPTO_MAP 10 ipsec-isakmp
set peer 192.168.1.2
set transform-set ts
match address CRYPTO_ACL
!
!
!
interface Loopback0
ip address 192.168.10.1 255.255.255.255
!
interface Loopback1
ip address 192.168.10.3 255.255.255.255
!
interface FastEthernet0/0
ip address 192.168.1.1 255.255.255.252
speed auto
crypto map CRYPTO_MAP
!
ip route 0.0.0.0 0.0.0.0 192.168.1.2
!
ip access-list extended CRYPTO_ACL
permit ip 192.168.10.0 0.0.0.255 10.10.2.0 0.0.0.255
Subscribe to:
Posts (Atom)