Configuring Ip Settings For Ipv4 And Ipv6 Traffic - McAfee M-1250 - Network Security Platform Configuration Manual

Ips configuration guide version 5.1
Hide thumbs Also See for M-1250 - Network Security Platform:
Table of Contents

Advertisement

McAfee® Network Security Platform 5.1
SYN Cookie
Inbound Threshold
Value
Outbound Threshold
Value
Reset un-finished 3
way handshake
connection

Configuring IP settings for IPv4 and IPv6 traffic

You can use McAfee Network Security Platform 5.1 to parse IPv4 and IPv6 traffic for
attacks (with the exception of DoS attacks in case of IPv6 traffic).
M-series Sensors parse IPv6 packets. N-450 Sensors do not parse IPv6 packets but can
pass them through.
TCP Parameter
SYN cookies are used to counter SYN flood attacks. With SYN cookies
enabled, whenever a new connection request arrives at a server, the
server sends back a SYN+ACK with an Initial Sequence Number (ISN)
uniquely generated using the information present in the incoming SYN
packet and a secret key. If the connection request is from a legitimate
host, the server gets back an ACK from the host.
Drop down choices:
Disabled:
Inbound Only:
Outbound Only:
Both Inbound and Outbound:
System events are displayed in the Threat Analyzer whenever you
enable or disable SYN cookie. For information on Threat Analyzer, see
System Status Monitoring Guide.
the
Caution:
a Network Security Sensor.
Note 1:
you don't have any ports in in-line mode, configure at least one port to be
inline.
Note 2:
if a Sensor is monitoring an interface containing VLAN-tagged traffic, a
separate sub-interface must be configured for each VLAN to ensure a
packet is not seen more than once.
Note 3:
The number of incomplete SYNs beyond which SYN cookies have to be
enabled for an incoming connection.
The number of incomplete SYNs beyond which SYN cookies have to be
enabled for an outgoing connection.
When enabled, automatically sends a TCP RST to the source when the
TCP SYN timer has expired for a connection.
Drop down choices:
Disabled
Set for all traffic
Set for DoS attack traffic only
Description
disable SYN cookies
use SYN cookies for inbound traffic only
use SYN cookies for outbound traffic only
use SYN cookies for inbound and outbound tra
Do not enable SYN cookies when passing MPLS traffic through
Sensors using SYN cookie settings must be in in-line mode. If
A Sensor will only see a packet once on any interface. However,
Syn cookie feature is not supported on N-450 Sensors.
: turned off
: all attack types
172
The IPS Sensor_Name node

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security platform

Table of Contents