Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Intrusion Prevention

Hi

 

At the moment I have no flags on the TCP and UDP Flood Protection. It seems the average packet size I've researched has little effect when flagged as I have dropped packets galore after setting these values, and then flagging them.

I have the following settings:

SYN Flood 12000/100 - FLAGGED - 12000/100 - FLAGGED

UDP Flood 12000/100 - NOT FLAGGED - 18000/100 - FLAGGED

TCP Flood 12000/1500 - NOT FLAGGED - 12000/1500 - NOT FLAGGED

ICMP/ICMPv6 Flood 1200/100 - FLAGGED - 300/100 FLAGGED

Dropped Source Routed Packets - FLAGGED

Disable ICMP/ICMPv6 Redirect Packet - FLAGGED

ARP Hardening - NOT FLAGGED

 

Any help would be appreciated as I feel a bit vulnerable at the moment and am new to Sophos and NGFW's in general!



This thread was automatically locked due to age.
Parents
  • Hi Samuel , 

    You may refer our administration guide and set the settings as per your requirement 

    SYN Flood 1200/100 - FLAGGED - 1200/100 - FLAGGED

    UDP Flood 5000/100 - FLAGGED - 5000/100 - FLAGGED

    TCP Flood 12000/1500 - NOT FLAGGED - 12000/1500 - NOT FLAGGED

    ICMP/ICMPv6 Flood 1200/100 - FLAGGED - 300/100 FLAGGED

    Dropped Source Routed Packets - FLAGGED

    Disable ICMP/ICMPv6 Redirect Packet - FLAGGED

    ARP Hardening - NOT FLAGGED

Reply
  • Hi Samuel , 

    You may refer our administration guide and set the settings as per your requirement 

    SYN Flood 1200/100 - FLAGGED - 1200/100 - FLAGGED

    UDP Flood 5000/100 - FLAGGED - 5000/100 - FLAGGED

    TCP Flood 12000/1500 - NOT FLAGGED - 12000/1500 - NOT FLAGGED

    ICMP/ICMPv6 Flood 1200/100 - FLAGGED - 300/100 FLAGGED

    Dropped Source Routed Packets - FLAGGED

    Disable ICMP/ICMPv6 Redirect Packet - FLAGGED

    ARP Hardening - NOT FLAGGED

Children
No Data