A fragmented SYN packet is anomalous, and as such it is suspect. To be cautious, block such unknown elements from entering your protected network.
|
Before You Begin |
|---|
|
For background information, read Understanding SYN Fragment Protection. |
You can use either J-Web or the CLI configuration editor to drop IP packets containing SYN fragments. The specified security zone is the one from which the packets originated.
This topic covers: