10-10-2014 12:14 PM
You can configure zone protection on your outside zone or zone that you are more concerned about.
You can define various action. In above example, I have asked firewall to block source IP for 300 secs if that ip is trying to scan the tcp port. You can customize the alert and threshold as well. Hope this helps. Thank you.
10-10-2014 12:33 PM
I have applied zone protection policy and it is set on alert.
I tried to port scan using nmap. however i could not see any hits using the command show counter global name flow_parse_l4_tcpsynfin.
Is there any way to see the zone protection logs.
10-10-2014 12:34 PM
Hi Westcon,
Zone Protection has ability to block port scan. You can find all relevant configuration in following link.
Let us know for additional granular information.
Regards,
Hardik Shah
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!