C H A P T E R
23-1
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
23
Preventing Network Attacks
This chapter describes how to prevent network attacks by configuring threat detection, TCP
normalization, limiting of TCP and UDP connections, and many other protection features.
This chapter includes the following sections:
•
Configuring Threat Detection, page 23-1
•
Configuring TCP Normalization, page 23-11
•
Configuring Connection Limits and Timeouts, page 23-14
•
Preventing IP Spoofing, page 23-16
•
Configuring the Fragment Size, page 23-17
•
Blocking Unwanted Connections, page 23-17
•
Configuring IP Audit for Basic IPS Support, page 23-18
Configuring Threat Detection
This section describes how to configure scanning threat detection and basic threat detection, and also
how to use statistics to analyze threats. Threat detection is available in single mode only.
This section includes the following topics:
•
Configuring Basic Threat Detection, page 23-1
•
Configuring Scanning Threat Detection, page 23-5
•
Configuring and Viewing Threat Statistics, page 23-7
Configuring Basic Threat Detection
Basic threat detection detects activity that might be related to an attack, such as a DoS attack. Basic
threat detection is enabled by default.
This section includes the following topics:
•
Basic Threat Detection Overview, page 23-2
•
Configuring Basic Threat Detection, page 23-2
•
Managing Basic Threat Statistics, page 23-4
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......