Administration Manual ip500pbxw – English
111
Enable Session Chaining
If this is enabled, TCP dynamic sessions also become
triggering sessions, which allows multi-level session
triggering
UDP Session Chaining
If this is enabled, UDP dynamic sessions also become
triggering sessions, which allows multi-level session
triggering
Binary Address
Replacement
Sets whether the destination IP address of the incoming
packet is replaced with the associated internal IP address to
allow NAT traversal
Address Translation Type Sets address replacement on a particular packet type.
Select
Apply
Intrusion Detection
This is used to detect and block incoming attempts to attack or block traffic to the site.
Select ‘Configure Intrusion Detection … ‘
The following screen is displayed
Enter the following parameters
Use Blacklist
Enables or disables blacklisting of an external host if the
firewall has detected an intrusion from that host. Access is
denied to that host for 10 minutes.
Use Victim Protection
Enables or disables the blocking of incoming broadcast Ping
commands for the period specified in Victim Protection Block
duration.
Victim Protection Block
Duration
The period for which incoming broadcast Pings are blocked.
The default setting is 600 seconds.
DOS Attack Block
Duration
If a Denial of Service attack is detected, traffic from that host
is blocked for the duration specified here. The default setting
is 1800 seconds.
Scan Attack Block
Duration
If scan activity from a host attempting to identify open ports
is detected, traffic from that host is blocked for the duration
specified here. The default setting is 86400 seconds (1 day).