UTT Technologies Chapter 11 Firewall
http://www.uttglobal.com
Page 178
Figure 11-1 Internal Attack Prevention Settings
Figure 11-2 External Attack Prevention Settings
1. Virus Prevention
Enable DDoS Prevention:
It is used to enable or disable DDoS prevention. If you
select the check box to enable this feature, it will effectively protect the Router against
popular DoS/DDoS attacks.
Enable IP Spoofing Prevention:
It allows you to enable or disable IP spoofing
defense. If you select the check box to enable this feature, it will effectively protect the
Device against IP spoofing attack. After you enable this feature, the Device will only
forward the packets whose source IP address is in the same subnet as the Device
LAN IP address. Note that in this case the hosts behind a L3 switch cannot access
the Internet through the Device.
Enable UDP Flood Prevention:
It allows you to enable or disable UDP flood defense.
If you select this check box to enable this feature, it will effectively protect the Device
against UDP flood attack. After you enable this feature, if the number of UDP packets
from one source IP address (e.g., 192.168.16.66) to a single port on a remote host
exceeds the threshold, the Device will consider that the LAN host with IP address
192.168.16.66 is performing UDP flood attack, and then randomly discard the further
UDP packets from that source to that destination. In most cases, leave
Threshold
the default value.
Enable ICMP Flood Prevention:
It allows you to enable or disable ICMP flood
defense. If you select this check box to enable this feature, it will effectively protect
the Device against ICMP flood attack. After you enable this feature, if the number of
ICMP packets from one source IP address (e.g., 192.168.16.16) to a single port on a
remote host exceeds the threshold, the Device will consider that the LAN host with IP
address 192.168.16.16 is performing ICMP flood attack, and then randomly discard
the further ICMP packets from that source to that destination. In most cases, leave
Threshold
the default value.
Enable SYN Flood Prevention:
It allows you to enable or disable SYN flood defense.
If you select this check box to enable this feature, it will effectively protect the Device
against SYN flood defense. After you enable this feature, if the number of SYN
packets from one source IP address (e.g., 192.168.16.36) to a single port on a
remote host exceeds the threshold, the Device will consider that the LAN host with IP