version 1.9, 2003/09/04 08:15:19 |
version 1.10, 2003/09/04 12:42:29 |
|
|
including: |
including: |
<ul> |
<ul> |
<li>packet tagging (e.g. filter on tags added by bridge based on MAC address) |
<li>packet tagging (e.g. filter on tags added by bridge based on MAC address) |
<li>stateful TCP normalization (reassemble tcp, normalize ttl and timeout) |
<li>stateful TCP normalization (prevent uptime calculation and NAT detection) |
<li>passive OS detection (filter or redirect connections based on source OS) |
<li>passive OS detection (filter or redirect connections based on source OS) |
<li>SYN proxy (protect servers against SYN flood attacks) |
<li>SYN proxy (protect servers against SYN flood attacks) |
<li>adaptive state timeouts (prevent state table overflows under attack) |
<li>adaptive state timeouts (prevent state table overflows under attack) |