You network contains an ISA Server 2006 computer named ISA1. You use Network Monitor to capture and analyze inbound traffic from the Internet to ISA1. You notice a high volume of TCP traffic that is sent in quick succession to random TCP ports on ISA1.
The flag settings of the traffic are shown in the following example.
TCP: Flags = 0x00:……….
TCP: ..0……=No urgent data
TCP: …0…..=Ackonwledgement field not significant TCP: ….0….=No Push function
TCP: …..0…=No Reset
TCP: ……0..=No Fin
This traffic slows the performance of ISA1.
You want to be able to create a custom alert that is triggered whenever ISA1 experiences traffic that uses invalid flag settings to discover open ports. You do not want the alert to be triggered by traffic that uses valid flag settings in an attempt to discover open ports. You want to accomplish this goal by selecting only the minimum number of options in the Intrusion Detection dialog box.
What should you do?
To answer, configure the appropriate option or options in the dialog box in the answer area.