cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
288
Views
0
Helpful
1
Replies

Pix Firewall Blocking

m-hennigan
Level 1
Level 1

Whats the most effiecent way to block packets with both the SYN and FIN flags set in a PIX running 6.3?

1 Reply 1

gfullage
Cisco Employee
Cisco Employee

If you enable the IDS function within the PIX, the PIX will flag this as an attack and if configured to drop attack-type packets, will do so.

See http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/gl.htm#wp1101884 for the configuration details for "ip audit".

See http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/63syslog/pixemsgs.htm#1055451 for details about the specific signatures the PIX IDS picks up. Signature 3041 is the one you're interested in.

Review Cisco Networking for a $25 gift card