![ZyXEL Communications P-660HN-F1A User Manual Download Page 204](http://html1.mh-extra.com/html/zyxel-communications/p-660hn-f1a/p-660hn-f1a_user-manual_944065204.webp)
Chapter 10 Firewalls
P-660HN-F1A User’s Guide
204
One Minute High This is the rate of new half-open sessions per minute that causes the
firewall to start deleting half-open sessions. When the rate of new
connection attempts rises above this number, the P-660HN-F1A
deletes half-open sessions as required to accommodate new
connection attempts.
For example, if you set the one minute high to 100, the P-660HN-F1A
starts deleting half-open sessions when more than 100 session
establishment attempts have been detected in the last minute. It stops
deleting half-open sessions when the number of session establishment
attempts detected in a minute goes below the number set as the one
minute low.
Maximum
Incomplete Low
This is the number of existing half-open sessions that causes the
firewall to stop deleting half-open sessions. The P-660HN-F1A
continues to delete half-open requests as necessary, until the number
of existing half-open sessions drops below this number.
Maximum
Incomplete High
This is the number of existing half-open sessions that causes the
firewall to start deleting half-open sessions. When the number of
existing half-open sessions rises above this number, the P-660HN-F1A
deletes half-open sessions as required to accommodate new
connection requests. Do not set Maximum Incomplete High to lower
than the current Maximum Incomplete Low number.
For example, if you set the maximum incomplete high to 100, the P-
660HN-F1A starts deleting half-open sessions when the number of
existing half-open sessions rises above 100. It stops deleting half-open
sessions when the number of existing half-open sessions drops below
the number set as the maximum incomplete low.
TCP Maximum
Incomplete
An unusually high number of half-open sessions with the same
destination host address could indicate that a DoS attack is being
launched against the host.
Specify the number of existing half-open TCP sessions with the same
destination host IP address that causes the firewall to start dropping
half-open sessions to that same destination host IP address. Enter a
number between 1 and 256. As a general rule, you should choose a
smaller number for a smaller network, a slower system or limited
bandwidth. The P-660HN-F1A sends alerts whenever the TCP
Maximum Incomplete is exceeded.
Action taken
when TCP
Maximum
Incomplete
reached
threshold
Select the action that P-660HN-F1A should take when the TCP
maximum incomplete threshold is reached. You can have the P-660HN-
F1A either:
Delete the oldest half open session when a new connection request
comes.
or
Deny new connection requests for the number of minutes that you
specify (between 1 and 255).
Apply
Click this to save your changes.
Cancel
Click this to restore your previously saved settings.
Table 57
Security > Firewall > Threshold (continued)
LABEL
DESCRIPTION
Summary of Contents for P-660HN-F1A
Page 2: ......
Page 10: ...Contents Overview P 660HN F1A User s Guide 10...
Page 20: ...Table of Contents P 660HN F1A User s Guide 20...
Page 21: ...21 PART I User s Guide...
Page 22: ...22...
Page 36: ...Chapter 2 Introducing the Web Configurator P 660HN F1A User s Guide 36...
Page 44: ...Chapter 3 Status Screens P 660HN F1A User s Guide 44...
Page 84: ...Chapter 4 Tutorials P 660HN F1A User s Guide 84 Physical Port 1 3 exclude port 4 3 Click Apply...
Page 88: ...Chapter 4 Tutorials P 660HN F1A User s Guide 88...
Page 103: ...103 PART II Technical Reference...
Page 104: ...104...
Page 142: ...Chapter 7 LAN Setup P 660HN F1A User s Guide 142...
Page 188: ...Chapter 9 Network Address Translation NAT P 660HN F1A User s Guide 188...
Page 210: ...Chapter 10 Firewalls P 660HN F1A User s Guide 210...
Page 236: ...Chapter 13 Certificates P 660HN F1A User s Guide 236...
Page 240: ...Chapter 14 Static Route P 660HN F1A User s Guide 240...
Page 276: ...Chapter 17 Dynamic DNS Setup P 660HN F1A User s Guide 276...
Page 288: ...Chapter 18 Remote Management P 660HN F1A User s Guide 288...
Page 344: ...Chapter 24 Troubleshooting P 660HN F1A User s Guide 344...
Page 376: ...Appendix A Setting up Your Computer s IP Address P 660HN F1A User s Guide 376...
Page 386: ...Appendix B Pop up Windows JavaScripts and Java Permissions P 660HN F1A User s Guide 386...
Page 396: ...Appendix C IP Addresses and Subnetting P 660HN F1A User s Guide 396...
Page 420: ...Appendix F Legal Information P 660HN F1A User s Guide 420...
Page 430: ...Index P 660HN F1A User s Guide 430...