Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Prime
Contributor

Signature related query

Want to  know what signatures can be put in prevent for below audit remarks -OS fingerprinting, host port scanning, fsl evasion, bruteforce

 

4 Replies
G_W_Albrecht
Legend Legend
Legend

I would assume that none of these can be prevented using signatures!

2. sk110873: How to configure Security Gateway to detect and prevent port scan

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
PhoneBoy
Admin
Admin

There is a Core protection called Fingerprint Scrambling, which is disabled by default.
As I recall, it has a pretty significant performance impact.

There are also a few different "brute force" IPS protections depending on the exact target:

image.png

Some of these are enabled by default in the Optimized and Strict profiles, a few are not due to their significant performance impact.

Guenther already linked to information on port scanning

I don't know what "fsl evasion" is, can you elaborate?

Prime
Contributor

sorry its please read as ssl evasion not fsl evasion.

PhoneBoy
Admin
Admin

Not familiar with this term please describe in more detail.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events