Firewall Filter - Rate-limit SYN packets to protect against a SYN flood attack

Information

Flood attacks try to overwhelm the target device in an attempt to consume all system resources. Common flood attacks have been successful using ICMP and TCP SYN packets, but flood attacks using other packet types are definitely possible. This section applies policers to protocols that are commonly used in flooding attacks.

Solution

Configure the firewall to protect against SYN flood attacks.

user@host# edit firewall family inet filter <NAME>
user@host# set term synflood-protect then policer <POLICER_NAME>

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-6

Plugin: Juniper

Control ID: 69e2218b60325e0c94ad5b9a3120e4d15b786df37d849d3d3bdb4de17d0c053e