11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 11: Intrusion Detection and PreventionDefault Packet HandlingThe <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong> provides default packethandling options to automatically block hosts that originateprobes and attacks. Logging options help you identifysites that exhibit suspicious behavior such as spoofing. Youcan use the information gathered to manually and permanentlyblock an offending site. In addition, you can blockports (by port number) to protect ports with known vulnerabilitiesfrom any incoming traffic. For more informationon log messages, see the following collection of FAQs:https://support.watchguard.com/advancedfaqs/log_main.aspThe <strong>Firebox</strong> <strong>System</strong> examines and handles packets accordingto default packet-handling options that you set. Thefirewall examines the source of the packet and its intendeddestination by IP address and port number. It also watchesfor patterns in successive packets that indicate unauthorizedattempts to access the network.The default packet-handling configuration determineswhether and how the firewall handles incoming communicationsthat appear to be attacks on a network. Packet handlingcan:• Reject potentially threatening packets• Automatically block all communication from a sourcesite• Add an event to the log• Send notification of potential security threatsBlocking spoofing attacksOne method that attackers use to gain access to your networkinvolves creating an electronic “false identity.” Withthis method, called “IP spoofing,” the attacker creates aTCP/IP packet that uses someone else’s IP address.Because routers use a packet’s destination address to forwardthe packet toward its destination, the packet’s sourceaddress is not validated until the packet reaches its destina-178 <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!