![Draytek VIGOR3220 SERIES User Manual Download Page 311](http://html.mh-extra.com/html/draytek/vigor3220-series/vigor3220-series_user-manual_2529396311.webp)
Vigor3220 Series User’s Guide
299
paused for 10 seconds.
Enable ICMP flood defense Check the box to activate the ICMP flood defense function.
Similar to the UDP flood defense function, once if the
Threshold of ICMP packets from Internet has exceeded the
defined value, the router will discard the ICMP echo
requests coming from the Internet.
The default setting for threshold and timeout are 250
packets per second and 10 seconds, respectively. That
means, when 250 packets per second received, they will be
regarded as “attack event” and the session will be paused
for 10 seconds.
Enable PortScan detection Port Scan attacks the Vigor router by sending lots of packets
to many ports in an attempt to find ignorant services would
respond. Check the box to activate the Port Scan
detection. Whenever detecting this malicious exploration
behavior by monitoring the port-scanning Threshold rate,
the Vigor router will send out a warning.
By default, the Vigor router sets the threshold as 2000
packets per second. That means, when 2000 packets per
second received, they will be regarded as “attack event”.
Block IP options
Check the box to activate the Block IP options function.
The Vigor router will ignore any IP packets with IP option
field in the datagram header. The reason for limitation is IP
option appears to be a vulnerability of the security for the
LAN because it will carry significant information, such as
security, TCC (closed user group) parameters, a series of
Internet addresses, routing messages...etc. An
eavesdropper outside might learn the details of your
private networks.
Block Land
Check the box to enforce the Vigor router to defense the
Land attacks. The Land attack combines the SYN attack
technology with IP spoofing. A Land attack occurs when an
attacker sends spoofed SYN packets with the identical
source and destination addresses, as well as the port
number to victims.
Block Smurf
Check the box to activate the Block Smurf function. The
Vigor router will ignore any broadcasting ICMP echo
request.
Block trace route
Check the box to enforce the Vigor router not to forward
any trace route packets.
Block SYN fragment
Check the box to activate the Block SYN fragment function.
The Vigor router will drop any packets having SYN flag and
more fragment bit set.
Block Fraggle Attack
Check the box to activate the Block fraggle Attack function.
Any broadcast UDP packets received from the Internet is
blocked.
Activating the DoS/DDoS defense functionality might block
some legal packets. For example, when you activate the
fraggle attack defense, all broadcast UDP packets coming
from the Internet are blocked. Therefore, the RIP packets
from the Internet might be dropped.
Block TCP flag scan
Check the box to activate the Block TCP flag scan function.
Any TCP packet with anomaly flag setting is dropped. Those
scanning activities include no flag scan, FIN without ACK
Summary of Contents for VIGOR3220 SERIES
Page 1: ......
Page 12: ......
Page 56: ...Vigor3220 Series User s Guide 44 This page is left blank ...
Page 87: ...Vigor3220 Series User s Guide 75 ...
Page 97: ...Vigor3220 Series User s Guide 85 ...
Page 130: ...Vigor3220 Series User s Guide 118 ...
Page 147: ...Vigor3220 Series User s Guide 135 ...
Page 198: ...Vigor3220 Series User s Guide 186 This page is left blank ...
Page 224: ...Vigor3220 Series User s Guide 212 This page is left blank ...
Page 294: ...Vigor3220 Series User s Guide 282 This page is left blank ...
Page 313: ...Vigor3220 Series User s Guide 301 ...
Page 357: ...Vigor3220 Series User s Guide 345 ...
Page 434: ...Vigor3220 Series User s Guide 422 4 Click OK to save the settings ...
Page 484: ...Vigor3220 Series User s Guide 472 This page is left blank ...
Page 530: ...Vigor3220 Series User s Guide 518 This page is left blank ...
Page 558: ...Vigor3220 Series User s Guide 546 ...
Page 565: ...Vigor3220 Series User s Guide 553 ...
Page 569: ...Vigor3220 Series User s Guide 557 ...
Page 571: ...Vigor3220 Series User s Guide 559 P Pa ar rt t I IX X D Dr ra ay yT Te ek k T To oo ol ls s ...
Page 576: ...Vigor3220 Series User s Guide 564 This page is left blank ...