1 / 15

Network Security 2

Network Security 2. Module 2: Configure Network Intrusion Detection and Prevention. Module 2: Configure Network Intrusion Detection and Prevention. Lesson 2.2 Configure Attack Guards on the PIX Security Appliance. SNMP Inspection. SNMP- Managed Device. 10.0.0.11. .19. Traps. Internet.

mirari
Download Presentation

Network Security 2

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. Network Security 2 Module 2: Configure Network Intrusion Detection and Prevention

  2. Module 2: Configure Network Intrusion Detection and Prevention Lesson 2.2 Configure Attack Guards on the PIX Security Appliance

  3. SNMP Inspection SNMP- Managed Device 10.0.0.11 .19 Traps Internet SNMP manager 10.0.0.3 SNMP v1 • snmp-map: To deny a specific version of SNMP • inspect snmp: To enable SNMP application inspection asa1(config)# snmp-map SNMP_DENY_V1 asa1(config-snmp-map)# deny version 1 . . . asa1(config)# policy-map global_policy asa1(config-pmap)# class class-default asa1(config-pmap-c)# inspectsnmpSNMP_DENY_V1 . . . asa1(config)# service-policy global_policy global

  4. DNS Inspection DNS Server Client 53 1050 Request Response • Monitors all UDP transactions on port 53: • Tracks DNS request ID and opens a connection slot • Closes connection slot immediately after answer is received • Translates the DNS A record • Before release 6.2: alias command • Release 6.2 and later: DNS record translation • Reassembles the DNS packet to verify its length (default = 512 bytes)

  5. FragGuard and Virtual Reassembly

  6. Default Fragment Configuration

  7. Fragment command

  8. Show fragment

  9. AAA Floodguard

  10. SYN Flood attack

  11. TCP Intercept

  12. SYN Cookies

  13. Embryonic connection limit

  14. Q and A

More Related