![ZyXEL Communications P-3202HN-Ba User Manual Download Page 151](http://html1.mh-extra.com/html/zyxel-communications/p-3202hn-ba/p-3202hn-ba_user-manual_945952151.webp)
Chapter 12 Firewalls
IAD User’s Guide
151
12.4 The Firewall Threshold Screen
For DoS
attacks, the IAD uses thresholds to determine when to start dropping
sessions that do not become fully established (half-open sessions). These
thresholds apply globally to all sessions.
For TCP, half-open means that the session has not reached the established state-
the TCP three-way handshake has not yet been completed. Under normal
circumstances, the application that initiates a session sends a SYN (synchronize)
packet to the receiving server. The receiver sends back an ACK (acknowledgment)
packet and its own SYN, and then the initiator responds with an ACK
(acknowledgment). After this handshake, a connection is established.
Figure 69
Three-Way Handshake
For UDP, half-open means that the firewall has detected no return traffic. An
unusually high number (or arrival rate) of half-open sessions could indicate a DOS
attack.
12.4.1 Threshold Values
If everything is working properly, you probably do not need to change the
threshold settings as the default threshold values should work for most small
offices. Tune these parameters when you believe the IAD has been receiving DoS
attacks that are not recorded in the logs or the logs show that the IAD is
classifying normal traffic as DoS attacks. Factors influencing choices for threshold
values are:
1
The maximum number of opened sessions.
2
The minimum capacity of server backlog in your LAN network.
3
The CPU power of servers in your LAN network.
4
Network bandwidth.
Summary of Contents for P-3202HN-Ba
Page 2: ......
Page 8: ...Safety Warnings IAD User s Guide 8...
Page 10: ...Contents Overview IAD User s Guide 10...
Page 18: ...Table of Contents IAD User s Guide 18...
Page 19: ...19 PART I User s Guide...
Page 20: ...20...
Page 28: ...Chapter 1 Introduction IAD User s Guide 28...
Page 39: ...39 PART II Technical Reference...
Page 40: ...40...
Page 50: ...Chapter 4 Status Screens IAD User s Guide 50...
Page 54: ...Chapter 5 Device Mode Screen IAD User s Guide 54...
Page 68: ...Chapter 7 LAN Setup IAD User s Guide 68...
Page 128: ...Chapter 10 Voice IAD User s Guide 128...
Page 158: ...Chapter 12 Firewalls IAD User s Guide 158...
Page 162: ...Chapter 13 Static Route IAD User s Guide 162...
Page 173: ...Chapter 14 Quality of Service QoS IAD User s Guide 173 Figure 81 QoS Class Example VoIP...
Page 174: ...Chapter 14 Quality of Service QoS IAD User s Guide 174 Figure 82 QoS Class Example Boss...
Page 182: ...Chapter 15 Dynamic DNS Setup IAD User s Guide 182...
Page 210: ...Chapter 17 Universal Plug and Play UPnP IAD User s Guide 210...
Page 214: ...Chapter 18 System IAD User s Guide 214...
Page 218: ...Chapter 19 Logs IAD User s Guide 218...
Page 224: ...Chapter 21 Diagnostic IAD User s Guide 224...
Page 230: ...Chapter 22 Troubleshooting IAD User s Guide 230...
Page 238: ...Chapter 23 Product Specifications IAD User s Guide 238...