|
Palo Alto Networks next-generation firewalls protect organizations from denial of service (DoS) attacks using a policy-based approach that ensures accurate detection. DoS protection policies can be deployed based on a combination of elements including type of attack, by volume both aggregate and classified with response options can include allow, alert, activate, maximum threshold and drop. Specific types of DoS attacks covered include:
- Flood Protection—Protects against SYN, ICMP, UDP, and other IP-based flooding attacks.
- Reconnaissance detection—Allows you to detect and block commonly used port scans and IP address sweeps that attackers run to find potential attack targets.
- Packet-based attack protection—Protects against large ICMP packets and ICMP fragment attacks.
|