| Netcreen Attack Detection and Defense Overview |
| Vendor | Juniper |
| Platform | Netscreen |
| Version | ScreenOS 6.2 |
| Firewalls - Juniper - Netscreen |
| Thursday, 27 August 2009 10:30 |
|
Below outlines Netcreens Attack Detection and Defense. This is by no means a full guide by acts as a general summary to the various terms and technologies. SCREENFeatures legacy security protection, such as SYN, UDP and ICMP floods, Port scans and certain OS-specific DoS attacks. Deep Inspection
Allows for inspection at the application layer for select protocols using stateful contexts. ScreenOS breaks down the protocol stream into inspectable fields. ScreenOS then uses DFA (Deterministic Finite Automation) to inspect these fields. URL Filtering
This allows for the use of 3rd Parties URL filtering options such as either SurfControl or Websense. Surf control includes an option called integrated mode which allows you to store filtering profiles upon the firewall itself. AV
This allows for HTTP, FTP, SMTP, POP3 and IMAP protocols to be inspected for viruses with the activation of a license. To enable and configure AV go to "Screening | Antivirus | Global". ALG
Protocols such as FTP, H.323 and other dynamic channel protocols can cause problems when creating the necessary firewall policies, due to the way thy dynamically choose/assign ports. To overcome this a subset of ALG`s were created for these protocols, which allow them to inspect the traffic/packets at the application layer and in turn allows the traffic through based on how the protocols function. |
Latest Articles
- Tool - SSLReport
- Brocade ADX - How to perform an image upgrade
- Cisco ASA reboots/crashes when running the command 'show service-policy interface outside set connection detail'
- Brocade ADX - Persistence
- How to define a port range on a Juniper SRX
- Path MTU Discovery (PMTUD) / Path MTU Black Holes
- Mitigating DoS attacks on a Cisco ASA
- How do I clear the Cisco ASA connection counters ?
- High CPU Usage on a Cisco CSS
- How to clone a MySQL database
- Brocade ADX - Configuring SSL
- Brocade ADX - Content Switching Rewrite
- Joomla - How to add a custom field
- BigIP F5 LTM - How to Create a Sorry Page with Image
- BigIP F5 LTM - TCP Syslog
- Cisco ASA - Traffic blocked when TCP syslog server is unreachable
- Excel - Unable to open file
- Brocade ADX - DoS Protection
- Brocade ADX - LoadBalancing Methods
- Brocade ADX - Healthcheck Elements
Popular
- Proxy ARP – SPLAT
- Check Point Commands
- IPSO - Commands
- ASA 8.3 - How to configure NAT
- vSphere - Creating User and Group Permissions
- PEMU - Free Cisco PIX Firewall Emulator / Simulator
- Juniper Netscreen Commands
- Juniper - NAT Explained
- Configuring Wireless Connectivity within Backtrack 4 r2
- ESX Convertor - The session is not authenticated
- How do I install snmpwalk / snmpget using Yum ?
- Netscreen - NSRP
- ESX - ViClient Cannot connect to host
- Troubleshooting a Netscreen Site 2 Site VPN
- Endpoint Connect Installation / Troubleshooting Guide
- ESXi - Connecting to a named pipe
- Check Point - How to Reset SIC
- ESXi White Box - HP DL140
- DNS / nslookup - How to find the root servers ?
- Netscreen - Routing Basics / Virtual Routers / PBR
