ADSL Bridge/Router User's Manual
64
Field
Description
Attack
Protection
Select
Enable
to use the built-in firewall
protections that prevent the following
common types of attacks:
o
IP Spoofing: Sending packets over the
WAN interface using an internal LAN
IP address as the source address.
o
Tear Drop: Sending packets that
contain overlapping fragments.
o
Smurf and Fraggle: Sending packets
that use the WAN or LAN IP
broadcast address as the source
address.
o
Land Attack: Sending packets that
use the same address as the source
and destination address.
o
Ping of Death: Illegal IP packet length.
DoS Protection
Click the Enable radio button to use the
following denial of service protections:
o
SYN DoS
o
ICMP DoS
o
Per-host DoS protection
Max Half open
TCP
Connection
Sets the percentage of concurrent IP
sessions that can be in the half-open
state. In ordinary TCP communication,
packets are in the half-open state only
briefly as a connection is being initiated;
the state changes to active when packets
are being exchanged, or closed when the
exchange is complete. TCP connections in
the half-open state can use up the
available IP sessions.
If the percentage is exceeded, then the
half-open sessions will be closed and
replaced with new sessions as they are
initiated.
Max ICMP
Connection
Sets the percentage of concurrent IP
sessions that can be used for ICMP
messages.
If the percentage is exceeded, then older
ICMP IP sessions will be replaced by new
sessions as the are initiated.
Max Single
Host
Connection
Sets the percentage of concurrent IP
session that can originate from a single
computer. This percentage should take
into account the number of hosts on the
LAN.
Summary of Contents for RTA100+
Page 2: ......
Page 12: ......
Page 18: ......
Page 22: ......
Page 24: ......
Page 30: ...ADSL Bridge Router User s Manual 24 RFC 1483 Bridge RFC 2364 PPPoA ...
Page 31: ...Error Style not defined Error Style not defined 25 RFC 1577 Router ...
Page 32: ......
Page 52: ......
Page 64: ......