- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Signature related query
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Signature related query
Want to know what signatures can be put in prevent for below audit remarks -OS fingerprinting, host port scanning, fsl evasion, bruteforce
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would assume that none of these can be prevented using signatures!
2. sk110873: How to configure Security Gateway to detect and prevent port scan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There is a Core protection called Fingerprint Scrambling, which is disabled by default.
As I recall, it has a pretty significant performance impact.
There are also a few different "brute force" IPS protections depending on the exact target:
Some of these are enabled by default in the Optimized and Strict profiles, a few are not due to their significant performance impact.
Guenther already linked to information on port scanning
I don't know what "fsl evasion" is, can you elaborate?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sorry its please read as ssl evasion not fsl evasion.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not familiar with this term please describe in more detail.
