Default Packet Handling
User Guide
181
network. Although there is some gain to leaving IP options
enabled, the risk generally outweighs the benefit.
From Policy Manager:
1
On the toolbar, click the Default Packet Handling icon.
You can also, from Policy Manager, select Setup
=>
Intrusion
Prevention
=>
Default Packet Handling.
The Default Packet Handling dialog box appears.
2
Select the checkbox marked
Block IP Options
.
Stopping SYN Flood attacks
A SYN Flood attack is a type of Denial of Service (DoS)
attack that seeks to prevent your public services (such as
email and Web servers) from being accessible to users on
the Internet.
To understand how SYN Flood works, consider a normal
TCP connection. A user tries to connect by way of a Web
browser to your server by sending what is called a SYN
segment. Your Web server acknowledges the browser by
sending what is called a SYN+ACK segment. When the
browser sees the SYN+ACK, it sends an ACK segment. The
server is ready to accept the URL request from the browser
when it sees the ACK statement. However, until the ACK
segment has been received, the server is “stuck”; it knows
the browser wants to communicate, but the connection is
not yet established. Many servers in use today can handle
only a finite number of these half-way completed connec-
tions at a time. They are stored in a backlog until they are
completed or time out. When the server’s backlog is full,
no new connections can be accepted.
A SYN Flood attack attempts to fill up the victim server’s
backlog by sending a flood of SYN segments without ever
sending an ACK. When the backlog fills up, the server will
be unavailable to users.
The WatchGuard Firebox System can help defend your
servers against a SYN Flood attack by tracking the number
of SYNs that are sent without a following ACK. If this
number exceeds the threshold you define, the SYN Flood
Содержание Firebox X10E
Страница 1: ...WatchGuard Firebox System User Guide WatchGuard Firebox System ...
Страница 12: ...xii WatchGuard Firebox System ...
Страница 44: ...Chapter 2 Service and Support 22 WatchGuard Firebox System ...
Страница 61: ...Cabling the Firebox User Guide 39 ...
Страница 68: ...Chapter 3 Getting Started 46 WatchGuard Firebox System ...
Страница 78: ...Chapter 4 Firebox Basics 56 WatchGuard Firebox System ...
Страница 156: ...Chapter 8 Configuring Filtered Services 134 WatchGuard Firebox System ...
Страница 182: ...Chapter 9 Configuring Proxied Services 160 WatchGuard Firebox System ...
Страница 220: ...Chapter 11 Intrusion Detection and Prevention 198 WatchGuard Firebox System ...
Страница 242: ...Chapter 12 Setting Up Logging and Notification 220 WatchGuard Firebox System ...
Страница 255: ...Working with Log Files User Guide 233 appear until the remote office Firebox has been properly configured ...
Страница 256: ...Chapter 13 Reviewing and Working with Log Files 234 WatchGuard Firebox System ...
Страница 274: ...Chapter 14 Generating Reports of Network Activity 252 WatchGuard Firebox System ...