66
C
HAPTER
5: C
ONFIGURING
THE
R
OUTER
Table 3
Intrusion Detection Parameters
Parameter
Defaults
Description
ntrusion Detection Feature
SPI and Anti-DoS
firewall
protection
Yes
The Intrusion Detection feature of the Router
limits the access of incoming traffic at the WAN
port. When the Stateful Packet Inspection (SPI)
feature is turned on, all incoming packets are
blocked except those types marked with a check
in the SPI section at the top of the screen.
RIP Defect
Disabled
If the router does not reply to an IPX RIP request
packet, it will stay in the input queue and not be
released. Accumulated packets could cause the
input queue to fill, causing severe problems for all
protocols. Enabling this feature prevents the
packets accumulating.
Discard Ping to
WAN
Don’t
discard
Prevents a ping on the Router’s WAN port from
being routed to the network.
Stateful Packet
Inspection
Enabled
This option allows you to select different
application types that are using dynamic port
numbers. If you wish to use Stateful Packet
Inspection (SPI) for blocking packets, click on the
Yes radio button in the “Enable SPI and Anti-DoS
firewall protection” field and then check the
inspection type that you need, such as Packet
Fragmentation, TCP Connection, UDP Session,
FTP Service and TFTP Service.
It is called a “stateful” packet inspection because
it examines the contents of the packet to
determine the state of the communication; i.e., it
ensures that the stated destination computer has
previously requested the current communication.
This is a way of ensuring that all communications
are initiated by the recipient computer and are
taking place only with sources that are known
and trusted from previous interactions. In
addition to being more rigorous in their
inspection of packets, stateful inspection firewalls
also close off ports until a connection to the
specific port is requested.
When particular types of traffic are checked, only
the particular type of traffic initiated from the
internal LAN will be allowed. For example, if the
user only checks FTP Service in the Stateful Packet
Inspection section, all incoming traffic will be
blocked except for FTP connections initiated from
the local LAN.
Summary of Contents for 3CRWER101A-75
Page 10: ...8 ABOUT THIS GUIDE ...
Page 18: ...16 CHAPTER 1 INTRODUCING THE ROUTER ...
Page 23: ...Setting up your computers for networking with the Router 21 Figure 8 WLAN Connections ...
Page 24: ...22 CHAPTER 2 INSTALLING THE ROUTER ...
Page 90: ...88 CHAPTER 5 CONFIGURING THE ROUTER ...
Page 104: ...102 APPENDIX B TECHNICAL SPECIFICATIONS ...
Page 112: ...110 APPENDIX D OBTAINING SUPPORT FOR YOUR PRODUCT ...
Page 122: ...120 ...