HCIE Security - Network Attack Overview

本文详细介绍了各种网络攻击类型,如洪水攻击、IP欺骗等,并提供了相应的防御措施,包括防火墙配置、源检测、流量抑制等。此外,还提到了特殊包过滤、扫描探测的防范方法以及通用防御技术,如uRPF和IP/MAC绑定。
摘要由CSDN通过智能技术生成

Network Attack Introduction

flow/flood

Like zombies from the Internet to attack some server.

ARP flood/SYN flood/Connection flood/ICMP flood/UDP flood/HTTP flood/SIP flood

threshold

source detection/fingerprint/flow suppressing

firewall defend arp-flood enable
firewall defend syn-flood enable
firewall defend tcp-illeage-session enable
firewall defend icmp-flood 
firewall defend udp-flood 
firewall defend http-flood enable

USG adopts tcp proxy and source authentication to defend SYN flood for internal servers.

abnormal packet

IP-spoofing, IP Fragment, Teardrop, Smurf, Ping of Death, Fraggle, WinNuke, Land, TCP Flag

firewall defend ip-spoofing enable
firewall defend ip-fragment enable
firewall defend teardrop enable
firewall defend smurf enable
firewall defend ping-of-death enable
firewall defend fraggle enable
firewall defend land enable
firewall defend tcp-flag enable
no need to turn on the above functions. you just need to understand those attacks.

special packet

firewall defend large-icmp enable
firewall defend icmp-unreachable enable

scanning and prying

ip or port scanning to identify potential attack targets or target weaknesses

firewall defend ip-sweep
firewall defend port-scan

General Technology of Defense

uRPF (unicast reverse path forwarding) checks if a packet’s source address has a route in FIB.

Blacklist can add user, source ip and destination ip manually or dynamically. Whitelist precedes blacklist.

[ngfw]firewall blacklist enable
firewall blacklist item user user-name [timeout minutes]

IP/MAC binding technology is only fit for static address assignment.

firewall mac-binding enable
firewall mac-binding ip-address mac-address

Port-mapping

Logging

Application Analysis

DDoS Intro

Appendix

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值