Hurricane 9200/S ADSL Ethernet Router User’s Guide
136
2. Configure the following settings as needed:
Field
Description
Black List Status
If you want the device to maintain a blacklist,
click the Enable radio button. Click the Disable
radio button if you do not want to maintain a list.
For more information, see “Managing the
Blacklist” on page 138.
Black List
Period(min)
Specifies the number of minutes that a
computer's IP address will remain on the blacklist
(i.e., all traffic originating from that computer will
be blocked from passing through any interface
on the ADSL/Ethernet router).
Attack Protection Click the Enable radio button to use the built-in
firewall protections that prevent the following
common types of attacks:
o
IP Spoofing: Sending packets over the WAN
interface using an internal LAN IP address
as the source address.
o
Tear Drop: Sending packets that contain
overlapping fragments.
o
Smurf and Fraggle: Sending packets that
use the WAN or LAN IP broadcast address
as the source address.
o
Land Attack: Sending packets that use the
same address as the source and destination
address.
o
Ping of Death: Illegal IP packet length.
DoS Protection
Click the Enable radio button to use the following
denial of service protections:
o
SYN DoS
o
ICMP DoS
o
Per-host DoS protection
Max Half open
TCP Connection
Sets the percentage of concurrent IP sessions
that can be in the half-open state. In ordinary
TCP communication, packets are in the half-
open state only briefly as a connection is being
initiated; the state changes to active when
packets are being exchanged, or closed when
the exchange is complete. TCP connections in
the half-open state can use up the available IP
sessions.
If the percentage is exceeded, then the half-open
sessions will be closed and replaced with new
sessions as they are initiated.
Max ICMP
Connection
Sets the percentage of concurrent IP sessions
that can be used for ICMP messages.
If the percentage is exceeded, then older ICMP
IP sessions will be replaced by new sessions as
the are initiated.
Max Single Host
Connection
Sets the percentage of concurrent IP session
that can originate from a single computer. This
percentage should take into account the number
of hosts on the LAN.
Summary of Contents for Hurricane 9200/S
Page 1: ...ADSL Ethernet Router User s Guide Revision 1 0 ...
Page 9: ...Table of Contents 9 C Glossary 191 Index 199 ...
Page 10: ......
Page 13: ...13 Part 1 Getting Started ...
Page 47: ...47 Part 2 Interfaces and Operating Modes ...
Page 88: ......
Page 89: ...89 Part 3 Routing and IP Related Features ...
Page 102: ......
Page 115: ...115 Part 4 Security Features ...
Page 159: ...159 Part 5 Administrative Tasks and System Monitoring ...
Page 198: ......