Chapter 10 Firewall Configuration
P-660HW-Dx User’s Guide
172
The following table describes the labels in this screen.
10.10 DoS Thresholds
For DoS attacks, the ZyXEL Device uses thresholds to determine when to drop sessions that
do not become fully established. These thresholds apply globally to all sessions.
You can use the default threshold values, or you can change them to values more suitable to
your security requirements.
Refer to
to configure thresholds.
10.10.1 Threshold Values
Tune these parameters when something is not working and after you have checked the firewall
counters. These default values should work fine for most small offices. Factors influencing
choices for threshold values are:
• The maximum number of opened sessions.
• The minimum capacity of server backlog in your LAN network.
• The CPU power of servers in your LAN network.
• Network bandwidth.
• Type of traffic for certain servers.
If your network is slower than average for any of these factors (especially if you have servers
that are slow or handle many tasks and are often busy), then the default values should be
reduced.
You should make any changes to the threshold values before you continue configuring
firewall rules.
Table 62
Firewall: Anti Probing
LABEL
DESCRIPTION
Respond to PING
on
The ZyXEL Device does not respond to any incoming Ping requests when
Disable
is selected.
Select
LAN
to reply to incoming LAN Ping requests.
Select
WAN
to reply to incoming WAN Ping requests.
Otherwise select
LAN & WAN
to reply to both incoming LAN and WAN Ping
requests.
Do Not Respond
to Requests for
Unauthorized
Services.
Select this option to prevent hackers from finding the ZyXEL Device by probing for
unused ports. If you select this option, the ZyXEL Device will not respond to port
request(s) for unused ports, thus leaving the unused ports and the ZyXEL Device
unseen. By default this option is not selected and the ZyXEL Device will reply with
an ICMP Port Unreachable packet for a port probe on its unused UDP ports, and a
TCP Reset packet for a port probe on its unused TCP ports.
Note that the probing packets must first traverse the ZyXEL Device's firewall
mechanism before reaching this anti-probing mechanism. Therefore if the firewall
mechanism blocks a probing packet, the ZyXEL Device reacts based on the
corresponding firewall policy to send a TCP reset packet for a blocked TCP
packet or an ICMP port-unreachable packet for a blocked UDP packets or just
drop the packets without sending a response packet.
Apply
Click
Apply
to save your changes to the ZyXEL Device.
Cancel
Click
Cancel
to begin configuring this screen afresh.
Summary of Contents for P-660HW-DX
Page 2: ......
Page 7: ...Safety Warnings P 660HW Dx User s Guide 7...
Page 8: ...Safety Warnings P 660HW Dx User s Guide 8...
Page 10: ...Contents Overview P 660HW Dx User s Guide 10...
Page 20: ...Table of Contents P 660HW Dx User s Guide 20...
Page 26: ...List of Figures P 660HW Dx User s Guide 26...
Page 31: ...31 PART I Introduction Introducing the ZyXEL Device 33 Introducing the Web Configurator 37...
Page 32: ...32...
Page 50: ...Chapter 2 Introducing the Web Configurator P 660HW Dx User s Guide 50...
Page 51: ...51 PART II Wizards Wizard Setup for Internet Access 53 Bandwidth Management Wizard 67...
Page 52: ...52...
Page 66: ...Chapter 3 Wizard Setup for Internet Access P 660HW Dx User s Guide 66...
Page 72: ...Chapter 4 Bandwidth Management Wizard P 660HW Dx User s Guide 72...
Page 74: ...74...
Page 92: ...Chapter 5 WAN Setup P 660HW Dx User s Guide 92...
Page 141: ...141 PART IV Security Firewalls 143 Firewall Configuration 155 Content Filtering 177...
Page 142: ...142...
Page 162: ...Chapter 10 Firewall Configuration P 660HW Dx User s Guide 162 Figure 88 Firewall Edit Rule...
Page 176: ...Chapter 10 Firewall Configuration P 660HW Dx User s Guide 176...
Page 180: ...Chapter 11 Content Filtering P 660HW Dx User s Guide 180...
Page 182: ...182...
Page 186: ...Chapter 12 Static Route P 660HW Dx User s Guide 186...
Page 202: ...Chapter 14 Dynamic DNS Setup P 660HW Dx User s Guide 202...
Page 224: ...Chapter 16 Universal Plug and Play UPnP P 660HW Dx User s Guide 224...
Page 226: ...226...
Page 232: ...Chapter 17 System P 660HW Dx User s Guide 232...
Page 250: ...Chapter 18 Logs P 660HW Dx User s Guide 250...
Page 256: ...Chapter 19 Tools P 660HW Dx User s Guide 256...
Page 264: ...264...
Page 330: ...Appendix F Internal SPTGEN P 660HW Dx User s Guide 330...
Page 332: ...Appendix G Command Interpreter P 660HW Dx User s Guide 332...
Page 344: ...Appendix J Splitters and Microfilters P 660HW Dx User s Guide 344...
Page 350: ...Appendix L Legal Information P 660HW Dx User s Guide 350...
Page 356: ...Appendix M Customer Support P 660HW Dx User s Guide 356...
Page 364: ...Index P 660HW Dx User s Guide 364...