Personal Stateful Firewall Overview
Supported Features ▀
Cisco ASR 5000 Series Product Overview ▄
OL-22938-02
UDP-based Attacks:
Invalid UDP echo response
Invalid UDP packet length
UDP checksum errors
Short UDP header length
UDP flood attack — Detected only in downlink direction
ICMP-based Attacks:
Invalid ICMP response
ICMP reply error
Invalid ICMP type packet
ICMP error message replay attacks
ICMP packets with duplicate sequence number
Short ICMP header length
Invalid ICMP packet length
ICMP flood attack — Detected only in downlink direction
Ping of death attacks
ICMP checksum errors
ICMP packets with destination unreachable message
Other DoS Attacks:
Port-scan attacks — Detected only in downlink direction
Protection against Port Scanning
Port scanning is a technique used to determine the states of TCP/UDP ports on a network host, and to map out hosts on
a network. Essentially, a port scan consists of sending a message to each port on the host, one at a time. The kind of
response received indicates whether the port is used, and can therefore be probed further for weakness. This way
hackers find potential weaknesses that can be exploited.
Stateful Firewall provides protection against port scanning by implementing port scan detection algorithms. Port-scan
attacks are only detected in the downlink direction—traffic from external network towards mobile subscribers.
Application-level Gateway Support
A stateful firewall while ensuring that only legitimate connections are allowed, also maintains the state of an allowed
connection. Some network applications require additional connections to be opened up in either direction and
information regarding such connections is sent in the application payload. For these applications to work properly, a
stateful firewall must inspect, analyze, and parse these application payloads to get the additional connection
information, and open partial connections/pinholes in the firewall to allow the connections.
Содержание ASR 5000 Series
Страница 1: ......
Страница 26: ......
Страница 48: ...New In Release 10 0 SCM Features Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 50: ......
Страница 58: ......
Страница 67: ...Product Service and Feature Licenses Default Licenses Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 68: ......
Страница 126: ......
Страница 138: ......
Страница 146: ......
Страница 218: ......
Страница 236: ......
Страница 356: ......
Страница 374: ......
Страница 422: ......
Страница 496: ......
Страница 572: ......
Страница 654: ......
Страница 700: ......
Страница 726: ......
Страница 784: ......
Страница 816: ......
Страница 839: ...Network Address Translation Overview How NAT Works Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 841: ...Network Address Translation Overview How NAT Works Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 844: ......
Страница 906: ......
Страница 926: ......
Страница 942: ......
Страница 943: ...Cisco ASR 5000 Series Product Overview OL 22938 02 Chapter 30 Technical Specifications ...
Страница 966: ......
Страница 967: ...Cisco ASR 5000 Series Product Overview OL 22938 02 Chapter 31 Safety Electrical and Environmental Certifications ...
Страница 972: ......