| Netcreen Attack Detection and Defense Overview |
| Vendor | Juniper |
| Platform | Netscreen |
| Version | ScreenOS 6.2 |
| Firewalls - Netscreen |
| Thursday, 27 August 2009 10:30 |
|
Below outlines Netcreens Attack Detection and Defense. This is by no means a full guide by acts as a general summary to the various terms and technologies. SCREENFeatures legacy security protection, such as SYN, UDP and ICMP floods, Port scans and certain OS-specific DoS attacks. Deep Inspection
Allows for inspection at the application layer for select protocols using stateful contexts. ScreenOS breaks down the protocol stream into inspectable fields. ScreenOS then uses DFA (Deterministic Finite Automation) to inspect these fields. URL Filtering
This allows for the use of 3rd Parties URL filtering options such as either SurfControl or Websense. Surf control includes an option called integrated mode which allows you to store filtering profiles upon the firewall itself. AV
This allows for HTTP, FTP, SMTP, POP3 and IMAP protocols to be inspected for viruses with the activation of a license. To enable and configure AV go to "Screening | Antivirus | Global". ALG
Protocols such as FTP, H.323 and other dynamic channel protocols can cause problems when creating the necessary firewall policies, due to the way thy dynamically choose/assign ports. To overcome this a subset of ALG`s were created for these protocols, which allow them to inspect the traffic/packets at the application layer and in turn allows the traffic through based on how the protocols function. |
Latest Articles
- F5 LTM VE 10.2.x - Interfaces not recognised
- Cisco ASA - Security Levels / NAT Control
- F5 LTM - OneConnect
- Django - CSRF verification failed. Request aborted.
- F5 LTM VE - Unable to attach to PCI device 02:01.00 for Interface 1.1
- F5 LTM - Connection Management
- Brocade ADX - FTP
- PKI - Chain of Trust
- Juniper SRX - Site to Site VPN using a Dynamic IP address
- F5 LTM - How do I perform software installations ?
- Juniper SRX - NAT
- Juniper SRX - How to configure a route based VPN
- Juniper SRX - Dynamic VPN
- Juniper SRX - How to configure a policy based VPN
- Brocade ADX - NAT
- Brocade ADX - CSW nested rules
- How do I upgrade a Juniper SRX Series gateway
- Cisco ASA - How do I capture ARP`s ?
- Juniper SRX - Configuring Source NAT with pool
- Running a packet capture on a Juniper SRX
Popular
- Proxy ARP – SPLAT
- Check Point Commands
- IPSO - Commands
- ASA 8.3 - How to configure NAT
- vSphere - Creating User and Group Permissions
- PEMU - Free Cisco PIX Firewall Emulator / Simulator
- Configuring Wireless Connectivity within Backtrack 4 r2
- Juniper Netscreen Commands
- Juniper Netscreen - NAT Explained
- How do I install snmpwalk / snmpget using Yum ?
- Netscreen - NSRP
- ESX Convertor - The session is not authenticated
- Troubleshooting a Netscreen Site 2 Site VPN
- ESX - ViClient Cannot connect to host
- Endpoint Connect Installation / Troubleshooting Guide
- Check Point - How to Reset SIC
- ESXi - Connecting to a named pipe
- Netscreen - Routing Basics / Virtual Routers / PBR
- Check Point Logging Troubleshooting Guide
- Configuring Windows 2008 R2 as an NTP Server
