Configuring TCP Land Attack Screen
This topic describes how to configure detection of a TCP land attack.
Land attacks occur when an attacker sends spoofed SYN packets containing the IP address of the victim as both the destination and the source IP address.
Configure the security screen option and attach it to the untrustZone as follows:
[edit] user@host# set security screen ids-option untrustScreen tcp land user@host# set security zones security-zone untrustZone screen untrustScreen