User guide
User Guide 141
CHAPTER 11 Protecting Your Network
From Attacks
The WatchGuard Firebox System can protect your network from many
types of attacks. In addition to the protection provided through filtered
and proxied services, the Firebox also gives you the tools to stop attacks–
such as the ones listed below–that services are not designed to defeat.
Spoofing attacks
Hackers alter packets to create a false identity for the purpose of
gaining access to your network.
Port space probes
Hackers attack port numbers sequentially in search of security
holes they can exploit.
Address space probes
Hackers attack IP addresses sequentially in search of security
holes they can exploit.
IP options attacks
Hackers use IP options to gain access to your network.
SYN flood attacks
Hackers try to deny service to legitimate users by overloading
your network with illegitimate TCP connection attempts.
The WatchGuard Firebox System provides default packet handling
options to automatically block hosts that originate probes and attacks.