Whether the USG6000 series supports IP spoofing attack defense

27

Yes.
When the USG6000 works in transparent or multi-egress mode, or policy-based routing is applied, IP spoofing attack defense cannot be configured.

Other related questions:
Enabling IP spoofing attack defense on the USG6000 series
The USG6000 looks up the routing table for the outgoing interfaces of reverse traffic destined to the source. If the incoming interface of the traffic and the outgoing interface of the reverse traffic are different, the packets are considered IP spoofing packets and discarded. Run the firewall defend ip-spoofing enable command to enable IP spoofing attack defense.

Whether the USG2000&5000 supports IP spoofing attack defense
Yes. When the USG2000&5000 works in transparent or multi-egress mode, or policy-based routing is applied, IP spoofing attack defense cannot be configured.

Enabling IP spoofing attack defense on the USG2000&5000 series
The USG2000&5000 looks up the routing table for the outgoing interfaces of reverse traffic destined to the source. If the incoming interface of the traffic and the outgoing interface of the reverse traffic are different, the packets are considered IP spoofing packets and discarded. Run the firewall defend ip-spoofing enable command to enable IP spoofing attack defense.

Whether the USG6000 series supports slow HTTP attack defense
No.

Whether the USG6000 series supports SIP flood attack defense
Yes.

If you have more questions, you can seek help from following ways:
To iKnow To Live Chat
Scroll to top