Layer 2 attacks are detected using implied rules for ARP table restrictions, fragment handling, connection timeouts and byte/length thresholds for packets.
DoS Detection:
SYN cookie-based protection from SYN flood attacks.
IP Spoofing Detection:
The validity of allowed addresses inside and outside the network are checked.
Traffic Anomaly Detection:
Heuristic rules detect unexpected traffic patterns that may suggest reconnaissance or attacks.