Zone protection and DoS protection
While layer 7 threats generally revolve around stealing data, blackmailing users through sophisticated phishing, or infecting hosts with complex and expensive zero-day vulnerabilities, protecting the network layer against DoS and other attacks is equally important. Protecting the system and the network is achieved in three different ways:
- System-wide settings that defend against maliciously crafted packets or attempts at evasion through manipulation
- Zone protection to protect the whole network against an onslaught of packets intended to bring the network to its knees
- DoS protection to more granularly protect resources from being overwhelmed
The system-wide settings are, unfortunately, not all neatly sorted in one place. I'll go over the most important ones.
System protection settings
A good deal of the global session-related settings can be accessed through the Device | Setup | Session tab. In the Session settings...