A TCP header with the SYN and FIN flags set is anomalous TCP behavior, causing various responses from the recipient, depending on the OS. Blocking packets with SYN and FIN flags helps prevent OS system probes.
Before You Begin |
---|
For background information, read Understanding Operating System Probes. |
You can use either J-Web or the CLI configuration editor to block packets with both the SYN and FIN flags set.
This topic covers:
To configure screens:
To configure zones:
- user@host# set security screen ids-option
syn-fin tcp syn-fin
- user@host# set security zones security-zone
zone screen syn-fin