1. Home
  2. Security Hardening
  3. TNS Best Practices SonicWALL 5.9
  4. SonicWALL – Flood Protection – Layer 2 – Threshold

SonicWALL – Flood Protection – Layer 2 – Threshold

Details

Flood Protection – Layer 2 – Threshold for SYN/RST/FIN flood blacklisting (SYNs / Sec)<=1000.

The SYN/RST/FIN Blacklisting feature is a list that contains devices that exceeded the SYN, RST, and FIN Blacklist attack threshold. The firewall device drops packets sent from blacklisted devices early in the packet evaluation process, enabling the firewall to handle greater amounts of these packets, providing a defense against attacks originating on local networks while also providing second-tier protection for WAN networks. Threshold for SYN/RST/FIN flood blacklisting (SYNs / Sec) – The maximum number of SYN, RST, and FIN packets allowed per second. The default is 1,000. This value should be larger than the SYN Proxy threshold value because blacklisting attempts to thwart more vigorous local attacks or severe attacks from a WAN network.

Solution

Navigate to Firewall Settings->Flood Protection->Layer 2 SYN/RST/FIN Flood Protection – MAC Blacklisting and set ‘Threshold for SYN/RST/FIN flood blacklisting (Packets / Sec)’ to a value of 1000 (default) or less.

This security hardening control applies to the following category of controls within NIST 800-53: System and Communications Protection.This control applies to the following type of system SonicWALL.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles