Cisco SPI Firewall Features Explained

I have been asked by Lawrence to write a brief note about SPI firewall features for CEH. With the installation of the third and final Cisco 877 router in HQ, security offered by packet-inspected (commonly known as SPI) firewall will protect the entire CEH network, shielding users from

  • IP Spoofing
  • Port Scanning
  • Ping of Death
  • SynFlood
  • DoS Attacks
  • TCP flag Attacks
  • Malformed Packet Attacks
Typically, each SPI firewall can further be fine-tuned to optimize flexibility in usage and friendliness. The Cisco 877 standard firewall is usually configured not to address UDP channel inspection (used by voip). Please let us know if this require policing too.

A third and final Cisco 877 router will be installed at client's premise on Thursday, pending confirmation.

Updated by Darren

0 comments: