Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Default ASA threat-detection and basic IPS

Status
Not open for further replies.

snootalope

IS-IT--Management
Jun 28, 2001
1,706
US
Anyone know, is the default setup on an asa 8.0 with threat-detection enabled and basic IPS turned on acceptable as it is? Or, do you think it's nessacary to go in and modify some of the threat-detection rate's?

What about TCP normalization, is it acceptable as is by default?

Will the defaults detect and stop a DoS attack?
 
DoS attacks can come in many forms. Usually you see it in a high amount of half connections. Throttling connection limits can help this. When it comes in forms of fragments or built in the data of a packet targeted at a service the firewall may not be the best resource. There are some default signatures but these can become quickly outdated. If you dont have any host based security and your are truly worried about Intrusion attempts than I would recommend getting a full IPS solution. You can view some of the signatures that the ASA comes with at the following link:





 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top