Chapter 11: Intrusion Detection and Prevention
180
WatchGuard Firebox System
Blocking port space and address space
attacks
Other methods that attackers use to gain access to net-
works and hosts are known as probes. Port space probes
are used to scan a host to find what services are running on
it. Address space probes scan a network to see which ser-
vices are running on the hosts inside that network. From
Policy Manager:
1
On the toolbar, click the Default Packet Handling icon.
You can also, from Policy Manager, select Setup
=>
Intrusion
Prevention
=>
Default Packet Handling.
The Default Packet Handling dialog box appears.
2
Select the checkbox marked
Block Port Space Probes
.
3
Select the checkbox marked
Block Address Space
Probes
.
Stopping IP options attacks
Another type of attack that can be used to disrupt your net-
work involves IP options in the packet header. IP options
are extensions of the Internet Protocol that are usually used
for debugging or for special applications. For example, if
you allow IP options, the attacker can use the options to
specify a route that helps him or her gain access to your
Summary of Contents for Firebox X1000
Page 1: ...WatchGuard Firebox System User Guide WatchGuard Firebox System...
Page 12: ...xii WatchGuard Firebox System...
Page 44: ...Chapter 2 Service and Support 22 WatchGuard Firebox System...
Page 61: ...Cabling the Firebox User Guide 39...
Page 68: ...Chapter 3 Getting Started 46 WatchGuard Firebox System...
Page 78: ...Chapter 4 Firebox Basics 56 WatchGuard Firebox System...
Page 156: ...Chapter 8 Configuring Filtered Services 134 WatchGuard Firebox System...
Page 182: ...Chapter 9 Configuring Proxied Services 160 WatchGuard Firebox System...
Page 220: ...Chapter 11 Intrusion Detection and Prevention 198 WatchGuard Firebox System...
Page 242: ...Chapter 12 Setting Up Logging and Notification 220 WatchGuard Firebox System...
Page 256: ...Chapter 13 Reviewing and Working with Log Files 234 WatchGuard Firebox System...
Page 274: ...Chapter 14 Generating Reports of Network Activity 252 WatchGuard Firebox System...