as someone mentioned out of state tcp packets are allowed by default. Anyone with more info that knows why its done this way?
It doesn't seem to be just a "miss", since it's documented in release notes:
Quote:
Out of state TCP packets are not dropped by default. To enable this feature, go to Global Properties > Stateful Inspection and select Drop out of state TCP packets. |