11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 11: Intrusion Detection and PreventionBlocking port space and address spaceattacksOther methods that attackers use to gain access to networksand hosts are known as probes. Port space probesare used to scan a host to find what services are running onit. Address space probes scan a network to see which servicesare running on the hosts inside that network. FromPolicy Manager:1 On the toolbar, click the Default Packet Handling icon.You can also, from Policy Manager, select Setup => IntrusionPrevention => Default Packet Handling.The Default Packet Handling dialog box appears.2 Select the checkbox marked Block Port Space Probes.3 Select the checkbox marked Block Address SpaceProbes.Stopping IP options attacksAnother type of attack that can be used to disrupt your networkinvolves IP options in the packet header. IP optionsare extensions of the Internet Protocol that are usually usedfor debugging or for special applications. For example, ifyou allow IP options, the attacker can use the options tospecify a route that helps him or her gain access to your180 <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!