![Sapido Gr-1100 User Manual Download Page 77](http://html1.mh-extra.com/html/sapido/gr-1100/gr-1100_user-manual_1198516077.webp)
77
4.7
Sequence Number Prediction Check
For TCP packets, sequence number is used to guard against accidental receipt of
unintended data and malicious use by the attackers if the ISN (Initial Sequence
Number) is generated randomly. Forged packets with valid sequence numbers
can be used to gain trust form the receiving host. Attackers can then gain access
to the compromised system. Note that this attack affects only the TCP packets
originated or terminated at the Internet Security Router.
4.8
Sequence Number Out of Range Check
Protect against TCP out of range sequence number attacks. An attacker can send
a TCP packet to cause an Intrusion Detection System (IDS) to become
unsynchronized with the data in a connection. Subsequent frames sent in that
connection may then be ignored by the IDS. This may indicate an unsuccessful
attempt to hijack a TCP session.
4.9
ICMP Verbose
Check or un-check this option to enable or disable protection against ICMP error
message attacks. ICMP messages can be used to fold your network with
undesired traffic.
4.10
Max IP Fragment Count
Input the maximum number of fragments the Firewall should allow for every IP
packet. This option is required if your connection to the ISP is through PPPoE.
This data is used during transmission or reception of IP fragments. When large
sized packets are sent via the GR-1100, the packets are chopped into fragments
as large as MTU (Maximum Transmission Unit). By default, this number is set to
45. If MTU of the interface is 1500(default for Ethernet), then there can be a
maximum of 45 fragments per IP packet. If the MTU is less, then there can be
more number of fragments and this number should be increased.
4.11
Minimum IP Fragment Size
Input the Minimum size of IP fragments to be allowed through Firewall. This limit
will not be enforced on the last fragment of the packet. If the Internet traffic is such
that it generates many small sized fragments, this value can be decreased. This
can be found if there are lots of packet losses, degradation in speed and if the
flowing log message is generated very often: “fragment of size less than
configured minimum fragment size detected”.
Summary of Contents for Gr-1100
Page 1: ...1 ...
Page 16: ...16 1 3 1 Product Appearance Introduction ...
Page 19: ...19 Step2 Click on Properties button Step3 Double click on Internet Protocol TCP IP ...
Page 24: ...24 If it can t work it will show Request timed out ...
Page 35: ...35 ISP and then click on Next button to connect to 3 2 2 LAN Setup ...
Page 125: ...125 ...
Page 169: ...169 Step 6 Input Username and Password of your own You will see like as below monitor screen ...
Page 267: ...267 ...
Page 270: ...270 Step7 Click on the My Services under Account Step8 And then click on Add Host Services ...