Check Point UTM-1 Edge User Manual page 418

Internet security appliance
Hide thumbs Also See for UTM-1 Edge:
Table of Contents

Advertisement

SmartDefense Categories
SynDefender
In a SYN attack, the attacker sends many SYN packets without finishing the three-way
handshake. This causes the attacked host to be unable to accept new connections.
You can protect against this attack by specifying a maximum amount of time for
completing handshakes.
Table 83: SynDefender Fields
In this field...
Do this...
Action
Specify what action to take when a SYN attack occurs, by selecting one of
the following:
A SYN attack is when more than 5 incomplete TCP handshakes are
detected within 10 seconds. A handshake is considered incomplete when it
exceeds the Maximum time for completing the handshake threshold.
Specify whether to issue logs for the events specified by the Log Mode
Track
parameter, by selecting one of the following:
404
Block. Block the packet. This is the default.
None. No action.
Log. Issue logs. This is the default.
None. Do not issue logs.
Check Point UTM-1 Edge User Guide

Hide quick links:

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the UTM-1 Edge and is the answer not in the manual?

Questions and answers

Subscribe to Our Youtube Channel

Table of Contents

Save PDF