[j-nsp] Rule to prevent illegitimal TCP attacks

jnunyez jnunyez at ac.upc.edu
Wed Jul 27 03:48:48 EDT 2005


I have an M7 router with an adaptative services PIC so it's able to accept 
make stateful firewall rules. M7 router has two networks attached, network A 
and network B.

I'm implementing a firewall and I want to know how to make this:

- A rule that accepts all TCP connections from subnetwork A to subnetwork B,    
so subnetwork B can send TCP packets for TCP connections initiated from 
subnetwork A. But subnetwork B shouldn't be able to send TCP packets that are 
not part of a connection initiated from subnetwork A. 

Is it possible?

Thanks,
Jose


More information about the juniper-nsp mailing list