A zone protection profile defends a whole zone against floods, scans and malformed packets. You create it under Network > Network Profiles > Zone Protection and attach it to the ingress zone, typically the Internet-facing zone, under Network > Zones. The firewall enforces it before security policy is even evaluated. That early placement is why it is cheap and effective: bad traffic is dropped before it consumes session resources. Zone protection is your first, broad layer of denial-of-service (DoS) defense.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.