[Contents] [Prev] [Next] [Index] [Report an Error]

Dropping IP Packets Containing SYN Fragments

A fragmented SYN packet is anomalous, and as such it is suspect. To be cautious, block such unknown elements from entering your protected network.

Before You Begin

For background information, read Understanding SYN Fragment Protection.

You can use either J-Web or the CLI configuration editor to drop IP packets containing SYN fragments. The specified security zone is the one from which the packets originated.

This topic covers:


[Contents] [Prev] [Next] [Index] [Report an Error]