Solved

Teardrop attack

Posted on 2006-10-24
2
1,704 Views
Last Modified: 2008-01-16
Hey guys

 i have netscreen firewall, i had a teardrop attack in my firewall from a selected ip range, can anyone help me how to block this attack or how to block this iprange from outside interface.. any ideas

Thanks for the help

Suresh
0
Comment
Question by:xavier_amala
2 Comments
 
LVL 11

Expert Comment

by:prueconsulting
ID: 17803721
Teardrop should not affect a netscreen firewall as its an IP fragment bug exploit for early linux and Windows systems.

0
 
LVL 32

Accepted Solution

by:
rsivanandan earned 500 total points
ID: 17805115
Is it pointed to the firewall itself ? or inside clients/via MIP/VIP ???

If so, a generic policy for some time would be good enough;

set policy id <id> from untrust to trust <Attacker> any any deny log

The above should do it.

Cheers,
Rajesh
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now