Help get this topic noticed by sharing it on
Twitter,
Facebook, or email.
Twitter,
Facebook, or email.
Firewall is dropping connections - we think we are experiencing a syn packet flood attack?
We are having problems with our firewall, can the LANGuardian generate an alert when ever a syn packet is seen.
Official
Response
-
You will need to add the IDS signature below to your LANGuardian here: https://ip address of LG/ids/editrule.cgi?sid=newrule
alert tcp any any -> any any (msg:"Local :: Syn Packet"; flags:S; classtype:policy-violation; sid:x; rev:1;)
If triggered this event will appear in the security events report on your system.
It is also possible to trend this activity. If you require further assistance please contact support@netforttechnologies.com
-
You will need to add the IDS signature below to your LANGuardian here: https://ip address of LG/ids/editrule.cgi?sid=newrule
alert tcp any any -> any any (msg:"Local :: Syn Packet"; flags:S; classtype:policy-violation; sid:x; rev:1;)
If triggered this event will appear in the security events report on your system.
It is also possible to trend this activity. If you require further assistance please contact support@netforttechnologies.com -
Loading Profile...



EMPLOYEE
