zone protection

cancel
Showing results for 
Search instead for 
Did you mean: 

zone protection

L3 Networker

How do we block synfin port scan.

14 REPLIES 14

L5 Sessionator

You can configure zone protection on your outside zone or zone that you are more concerned about.

zone_protect.JPG

You can define various action. In above example, I have asked firewall to block source IP for 300 secs if that ip is trying to scan the tcp port. You can customize the alert and threshold as well. Hope this helps. Thank you.

L5 Sessionator

Westcon2

Have you tried the syn flood or TCP port scan in zone protection profile ? Is it not working for synfin port scan ?

I have applied zone protection policy and it is set on alert.

I tried to port scan using nmap. however i could not see any hits using the command show counter global name flow_parse_l4_tcpsynfin.

Is there any way to see the zone protection logs.

L6 Presenter

Hi Westcon,

Zone Protection has ability to block port scan. You can find all relevant configuration in following link.

Understanding DoS Protection

Let us know for additional granular information.

Regards,

Hardik Shah

Hi Westcon,

You can find zone protection logs in Monitor > Threat.

It seems Nmap may not be crossing zone protection scan limit/second.

Would  you share zone protection configuration along with Nmp scan rate ?

Regards,

Hardik Shah

Do you see any drops in the output of this command:

show zone-protection zone <zone-name>

L3 Networker

I am using two firewalls. once is having an old setup and the other recently deployed.

The out put of the command show counter global name flow_parse_l4_tcpsynfin is as below. 

My question is that does the firewall have the ability to drop the synfin packets automatically or do we need to apply the zp or dos policy.

Below is the output

Firewall 1 without zone protection

Name:           flow_parse_l4_tcpsynfin

Value:          5709

Severity:       Drop

Category:       flow

Aspect:         parse

Desciption:     Packets dropped: invalid TCP flags (SYN+FIN+*)

Firewall 2

admin@Lab-Firewall> show counter global name flow_parse_l4_tcpsynfin

Name:           flow_parse_l4_tcpsynfin

Value:          0

Severity:       Drop

Category:       flow

Aspect:         parse

Desciption:     Packets dropped: invalid TCP flags (SYN+FIN+*)

Hi Westcon,

Provide us following output. Whic will list all kind of latest drop.

1. Execute command "show counter global filter delta sev drop"

2. Run NMAP

3. Run again "show counter global filter delta sev drop"


Provide us output for 3rd pointer


Regards,

Hardik Shah

Hi Westcon2,

If zone protection is triggered, you can see it under threat logs.

scan.JPG

If you have flood attacks, you will Flood attacks warning as well.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!