Chapter 23 Preventing Network Attacks; Configuring Threat Detection; Configuring Basic Threat Detection - Cisco PIX 500 Series Configuration Manual

Security appliance command line
Hide thumbs Also See for PIX 500 Series:
Table of Contents

Advertisement

Preventing Network Attacks
This chapter describes how to prevent network attacks by configuring threat detection, TCP
normalization, limiting of TCP and UDP connections, and many other protection features.
This chapter includes the following sections:

Configuring Threat Detection

This section describes how to configure scanning threat detection and basic threat detection, and also
how to use statistics to analyze threats. Threat detection is available in single mode only.
This section includes the following topics:

Configuring Basic Threat Detection

Basic threat detection detects activity that might be related to an attack, such as a DoS attack. Basic
threat detection is enabled by default.
This section includes the following topics:
OL-12172-03
Configuring Threat Detection, page 23-1
Configuring TCP Normalization, page 23-11
Configuring Connection Limits and Timeouts, page 23-14
Preventing IP Spoofing, page 23-16
Configuring the Fragment Size, page 23-17
Blocking Unwanted Connections, page 23-17
Configuring IP Audit for Basic IPS Support, page 23-18
Configuring Basic Threat Detection, page 23-1
Configuring Scanning Threat Detection, page 23-5
Configuring and Viewing Threat Statistics, page 23-7
Basic Threat Detection Overview, page 23-2
Configuring Basic Threat Detection, page 23-2
Managing Basic Threat Statistics, page 23-4
C H A P T E R
Cisco Security Appliance Command Line Configuration Guide
23
23-1

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5500 series

Table of Contents