370
Preventing attacks
Enabling protection for logical network interfaces
Prerequisites
None.
To configure SYN flood protection
1
In the SGMI, in the left pane, under Assets, click
Network
.
2
In the right pane, on the Network Interfaces tab, select the network interface on which you want to
enable protection, and then click
Properties
.
3
In the Network Interface Properties dialog box, on the General tab, in the SYN Flood restriction
level drop-down list, select a level of SYN flood protection.
4
Click
OK
.
5
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
For further information related to this topic, see the following:
■
“Network Interface Properties—General tab”
Creating a SYN flood allowed host list
The SYN flood allowed hosts list is a compilation of all of the IP addresses that you would like the SYN
flood protection feature to ignore when determining if the security gateway is under a SYN flood
attack.
Prerequisites
None.
To create a SYN flood allowed host list
1
In the SGMI, in the left pane, under System, click
Administration
.
2
In the right pane, on the SYN Flood Allowed Hosts tab, in the Allowed Hosts text box, type an IP
address, and then click
Add
.
3
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
For further information related to the topic, see the following:
■
“Configuring SYN flood protection”
Enabling spoof protection
Enabling spoof protection on an interface instructs the security gateway to examine packets that
arrive, and determine if it is the correct interface. For example, publicly addressed packets that arrive
on a private interface are often an indication that the packet was spoofed. Therefore, using this
feature, and correctly defining the allowed IP address range for each interface, can often catch spoofed
addresses. Changes made here take affect immediately after activating the new configuration.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...