Chapter 9

1: What is meant by Java blocking in the IOS Firewall world?
A1: Answer: IOS Firewall can stop Java applets from being downloaded from Web sites that are not explicitly permitted to send Java applets to the machines behind the firewall.
2: How does the IOS Firewall protect against TCP SYN floods?
A2: Answer: IOS Firewall protects against SYN floods by monitoring the total number of half-open TCP connections as well as new TCP connections being opened each minute. If these numbers reach a configurable threshold, it starts tearing down the half-open connections.
3: How does FTP work through the IOS Firewall?
A3: Answer: CBAC monitors the FTP connections being established from behind the firewall. When CBAC detects a new FTP session, it watches ...

Get Network Security Principles and Practices now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.