This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Intrusion Prevention

Hi

 

At the moment I have no flags on the TCP and UDP Flood Protection. It seems the average packet size I've researched has little effect when flagged as I have dropped packets galore after setting these values, and then flagging them.

I have the following settings:

SYN Flood 12000/100 - FLAGGED - 12000/100 - FLAGGED

UDP Flood 12000/100 - NOT FLAGGED - 18000/100 - FLAGGED

TCP Flood 12000/1500 - NOT FLAGGED - 12000/1500 - NOT FLAGGED

ICMP/ICMPv6 Flood 1200/100 - FLAGGED - 300/100 FLAGGED

Dropped Source Routed Packets - FLAGGED

Disable ICMP/ICMPv6 Redirect Packet - FLAGGED

ARP Hardening - NOT FLAGGED

 

Any help would be appreciated as I feel a bit vulnerable at the moment and am new to Sophos and NGFW's in general!



This thread was automatically locked due to age.
Parents
  • Hi Samuel , 

    You may refer our administration guide and set the settings as per your requirement 

    SYN Flood 1200/100 - FLAGGED - 1200/100 - FLAGGED

    UDP Flood 5000/100 - FLAGGED - 5000/100 - FLAGGED

    TCP Flood 12000/1500 - NOT FLAGGED - 12000/1500 - NOT FLAGGED

    ICMP/ICMPv6 Flood 1200/100 - FLAGGED - 300/100 FLAGGED

    Dropped Source Routed Packets - FLAGGED

    Disable ICMP/ICMPv6 Redirect Packet - FLAGGED

    ARP Hardening - NOT FLAGGED

    Regards,

    Aditya Patel
    Global Escalation Support Engineer | Sophos Technical Support

    Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

Reply
  • Hi Samuel , 

    You may refer our administration guide and set the settings as per your requirement 

    SYN Flood 1200/100 - FLAGGED - 1200/100 - FLAGGED

    UDP Flood 5000/100 - FLAGGED - 5000/100 - FLAGGED

    TCP Flood 12000/1500 - NOT FLAGGED - 12000/1500 - NOT FLAGGED

    ICMP/ICMPv6 Flood 1200/100 - FLAGGED - 300/100 FLAGGED

    Dropped Source Routed Packets - FLAGGED

    Disable ICMP/ICMPv6 Redirect Packet - FLAGGED

    ARP Hardening - NOT FLAGGED

    Regards,

    Aditya Patel
    Global Escalation Support Engineer | Sophos Technical Support

    Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

Children
No Data