Does the IG200/IG2000 use different responses for different intrusion conditions such as TCP packets with bad sequence numbers vs. SYN attacks?
Blocking is the response to any threshold violation. Traffic will be dropped for a configurable time period, and then the connection will be reevaluated to determine if behavior has been remedied. If violations persist, all traffic from the offending source will be dropped pending administrator intervention. For TCP connections, you can choose whether to drop an offending packet or drop the connection.