- Network > Network Profiles > Zone Protection > Reconnaissance Protection
The following settings define reconnaissance protection:
Zone Protection Profile Settings—Reconnaissance Protection
TCP Port Scan
Enableconfigures the profile to enable protection against TCP port scans.
UDP Port Scan
Enableconfigures the profile to enable protection against UDP port scans.
Enableconfigures the profile to enable protection against host sweeps.
Action that the system will take in response to the corresponding reconnaissance attempt:
Block all Reconnaissance scans except your internal vulnerability testing scans.
Time interval, in seconds, for TCP or UDP port scan detection (range is 2-65,535; default is 2).
Time interval, in seconds, for host sweep detection (range is 2-65,535; default is 10).
Number of scanned port events or host sweep events within the specified time interval that triggers the Action (range is 2-65,535; default is 100).
Use the default event threshold to log a few packets for analysis before blocking reconnaissance attempts.
Source Address Exclusion
IP addresses whitelisted from the reconnaissance protection. The list supports a maximum of 20 IP addresses or Netmask address objects.
Whitelist only IP addresses for trusted internal groups that perform “white hat” vulnerability testing.