ScreenOS:Untrust Zone - Disable TCP Reset

Information

Disabling TCP Reset on the Untrust zone will help reduce information disclosure in the event the firewall is being probed for open ports. A typical example would be a TCP SYN scan looking for open ports where the firewall would normally respond with a TCP Reset if a request port is not available due to configured policy, which allows an attacker to easily map open vs closed ports on the firewall. While this does not completely protect you against scanning activity this limits the information available for a would be attacker.

Solution

You may navigate to the following ScreenOS menu location: Configuration > Network > Zones. Once there you may select the appropriate zone to further edit.

See Also

https://www.juniper.net/techpubs/en_US/screenos6.3.0/information-products/pathway-pages/screenos/index.html

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-10

Plugin: Juniper

Control ID: 0d82aaa51d8f000a87abd7d22a4d56b548b63b2525a7af5ee1106755fe30ffb3