DoS Protection
StoneGate NextGen Firewall provides
protection against illegal input and traffic flood DoS attacks without disturbing legitimate
network traffic.
Benefits:
- Protects Web services from DoS/DDoS attacks
- Does not disturb legitimate network traffic.
TCP SYN flood attacks are stopped by mitigating the incoming connection attempts from spoofed
address sources under an attack, and preventing them from reaching the target system. StoneGate
Firewall quickly identifies the spoofed connection sources and blocks them, while allowing valid
user connections to pass through.
UDP flood DoS attacks are controlled by rate-limiting the incoming UDP datagrams against the
protected Web service.
Illegal input DoS (aka. trivial DoS) attacks are detected and prevented by StoneGate Firewall
System Policy template by default.