- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-11-2012 01:04 PM
hi : In regard to the settings for Port Scans and Host Sweeps:
What counts as an event toward reaching the threshold? Is it a SYN packet or are other types of packets counted?
Thanks
01-24-2012 01:48 PM
The Zone Protection doc here covers this Reconnaissance protection on page 4:
It states:
"Reconnaissance protection is used to prevent/alert administrators on reconnaissance attempts like ports scans, ICMP sweep. Unlike the flood settings, threshold settings are applicable to hosts in the zone where reconnaissance protection is configured.Interval: Time between successive probes for open ports. For host sweep it is the time interval between successive probes (ICMP/TCP/UDP) to the network"
So, Since TCP uses SYN, that should count for TCP, and as far as other protocols ICMP and UDP they do not have SYN packets, but are covered by this protection, so that should also be covered.
I hope that makes a little sense.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!