CHAPT ER
27-1
Cisco ASDM User Guide
OL-16647-01
27
Configuring Advanced Firewall Protection
This chapter describes how to prevent network attacks by configuring protection features, and includes
the following sections:
Configuring Threat Detection, page 27-1
Configuring Connection Settings, page 27-6
Configuring IP Audit, page 27-10
Configuring the Fragment Size, page 27-17
Configuring Anti-Spoofing, page 27-20
Configuring TCP Options, page 27-20
Configuring Global Timeouts, page 27-23
Note For Sun RPC server and encrypted traffic inspection settings, which you configure in the
Configuration > Firewall > Advanced area (along with many of the topics in this chapter), see
Chapter 24, “Configuring Application Layer Protocol Inspection.”

Configuring Threat Detection

This section describes how to configure scanning threat detection and basic threat detection. Threat
detection is available in single mode only.
This section includes the following topics:
Configuring Basic Threat Detection, page 27-1
Configuring Scanning Threat Detection, page 27-3
Configuring Threat Statistics, page 27-4
To view threat detection statistics, see the “Firewall Dashboard Tab” section on page 1-20.

Configuring Basic Threat Detection

Basic threat detection detects activity that might be related to an attack, such as a DoS attack. Basic
threat detection is enabled by default.
This section includes the following topics: