Cisco Guard & bot.net attack ? pls help me!! expert
I have some questions about Cisco guard:
1: Guard can defense spoof IP attack only, right?
2: Can Guard defense BOT.NET attack (real IP attack)? If yeah, how to do it?
3: Guard use "dst_ip/dst_ip_ratio/dst_port/dst_port_ratio/global/protocol/src_ip/src_ip_many_dst_ips/src_ip_many_ports" to check attack traffic, right?
4:If work in netflow ,so Guard only detect attack base on ?source IP address, destination IP address, source port number, destination port number, protocol type, type of services, and the router input interface? only, is it right?
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...