Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Configuring IP Protocol Scanning

This topic describes how to configure detection of an IP protocol scanning attack.

An IP protocol scanning attack typically involves probing a target system by sending packets with varying IP protocol numbers to identify which protocols are supported or active This kind of reconnaissance can be a precursor to more targeted attacks.

To enable detection of IP protocol scanning attack:

  1. Configure interfaces and assign IP addresses to the interfaces.
  2. Configure security zones trustZone and untrustZone and assign interfaces to them.
  3. Configure security policies from untrustZone to trustZone.
  4. Configure the security screen option and attach it to the untrustZone.
  5. Configure syslog.
  6. Commit the configuration.