Hi,
Doing a "conduit" to "access-list" conversion in the PIX, I noticed there were no equivalent to the "embryonic" parameter in the static command :
static (DMZ/Internet) <ip address> <ip address> 0 500
where 500 is the number of half-sessions (embryonic) that can be a opened before the PIX reacts. This protects agains Syn attacks.
Anybody knows how we can control this parameter in an Access-list environment on the PIX ?
Thanks !
Steve Saindon
Network Consultant
Interreseau-Conseils Inc.