DefensePro User Guide
Security Configuration
128
Document ID: RDWR-DP-V0602_UG1201
Configuring Global SYN Flood Protection
A SYN flood attack is usually aimed at specific servers with the intention of consuming the server’s
resources. However, you configure SYN Protection as a Network Protection to allow easier protection
of multiple network elements.
Before you configure SYN profiles for the network-protection policy, ensure the following:
•
SYN Protection is enabled the SYN Flood Protection global parameters are configured.
•
The Session table Lookup Mode is Full Layer 4. For more information, see
.
To configure global SYN Flood Protection
1. In the Configuration perspective Security Settings tab navigation pane, select SYN Flood
Protection Settings.
2. Configure the parameters; and then, click
(Submit) to submit the changes.
Enable High Port
Response
Specifies whether the Anti-Scanning Protection emphasizes inspecting
scans aimed at ports greater than 1024 (that is, usually unassigned
ports).
Values:
•
Enabled—The Anti-Scanning Protection emphasizes inspecting scans
aimed at ports greater than 1024. Select this checkbox when using
applications that utilize standard system ports (that is, port values
less than 1024).
•
Disabled—The Anti-Scanning Protection treats all the scan activities
equally. Clear this checkbox when using applications utilizing non-
standard ports (that is, port values greater than 1024).
Default: Enabled
Note:
When the parameter is enabled and you have legitimate
applications using high-range ports, the DefensePro device is
prone to more false positives.
Maximal Blocking
Duration
The maximum time, in seconds, that the Anti-Scanning Protection blocks
the source of a scan—if that source continues to scan the network.
Values: 20–3600
Default: 80
Note:
This setting overrides the maximum time set in the suspend
table parameters.
Table 61: Global Anti-Scanning Settings
Parameter
Description
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...