Learn how to configure reconnaissance protection to prevent
attackers from probing your network for vulnerabilities.
Configure one of the following
Reconnaissance Protection actions
for the firewall to take in response to the corresponding reconnaissance attempt:
Allow—The firewall allows the port scan or host sweep
reconnaissance to continue.
Alert—The firewall generates an alert for each port
scan or host sweep that matches the configured threshold within
the specified time interval. Alert is the default action.
Block—The firewall drops all subsequent packets from
the source to the destination for the remainder of the specified
time interval.
Block IP—The firewall drops all subsequent packets
for the specified Duration, in seconds (the
range is 1-3,600). Track By determines whether
the firewall blocks source or source-and-destination traffic.