SonicWALL - Flood Protection - Layer 2 - All Interfaces

Information

The SYN/RST/FIN Blacklisting feature is a list that contains devices that exceeded the SYN, RST, and FIN Blacklist attack threshold. The firewall device drops packets sent from blacklisted devices early in the packet evaluation process, enabling the firewall to handle greater amounts of these packets, providing a defense against attacks originating on local networks while also providing second-tier protection for WAN networks.

Solution

Navigate to Firewall Settings->Flood Protection->Layer 2 SYN/RST/FIN Flood Protection - MAC Blacklisting and set 'Enable SYN/RST/FIN flood blacklisting on all interfaces' to true.

Item Details

Audit Name: TNS SonicWALL v5.9

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5

Plugin: SonicWALL

Control ID: c682b9d8a31b1a0b3c0287665baab079f4757f7d6046f878ace554249d97119b