Adtran : Enable firewall syn-flood detection

Information

SYN flooding is a well-known denial-of-service attack on TCP-based services. TCP requires a three-way
handshake before actual communications begin between two hosts. A server must allocate resources to
process new connection requests that are received. A potential intruder is capable of transmitting large
amounts of service requests (in a very short period of time), causing servers to allocate all resources to
process the phony incoming requests. Using the 'ip firewall check syn-flood' command configures the
AOS stateful inspection firewall to filter out phony service requests and allow only legitimate requests to pass through.

Solution

Run the following command to enable syn-flood detection :


ip firewall check syn-flood

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5

Plugin: Adtran

Control ID: 73890af77f162c63d885c720a8049e50cd03f5c1cb2a441974a6c6e6be98c3bb