- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-26-2013 10:57 PM
Hi guys ,
Is it possible for PAN to block asynchronous tcp and RST packets to prevent attack ?
Regards,
Bryan
08-27-2013 07:01 AM
Hi...By asynchronous, I assume you mean TCP packets that do not follow the TCP 3-way handshake. The default behavior of the PA is to perform stateful inspection and will drop packets that did not conform to the 3-way TCP handshake. Here's how to enable/disable this feature: How to Set the Firewall to Reject non-Syn First Packet?
Thanks.
08-27-2013 08:25 AM
PANFW can act upon malicious TCP packets ( used for port scans and reconnaisance ) using the zone protection profile as shown below.
As I understand the zone protection is for incoming traffic.
That is if you want to protect DMZ then you should apply your zone-protection on the Untrust zone (facing Internet) and the Trust zone (facing your LAN - if you wish to protect from inside threats aswell (for example an overtaken client is being used to DDoS/DoS your DMZ devices)).
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!