Chapter 10 Firewall Configuration
P-660HW-Dx User’s Guide
173
10.10.2 Half-Open Sessions
An unusually high number of half-open sessions (either an absolute number or measured as
the arrival rate) could indicate that a Denial of Service attack is occurring. For TCP, "half-
open" means that the session has not reached the established state-the TCP three-way
handshake has not yet been completed (see
). For UDP, "half-open"
means that the firewall has detected no return traffic.
The ZyXEL Device measures both the total number of existing half-open sessions and the rate
of session establishment attempts. Both TCP and UDP half-open sessions are counted in the
total number and rate measurements. Measurements are made once a minute.
When the number of existing half-open sessions rises above a threshold (
max-incomplete
high
), the ZyXEL Device starts deleting half-open sessions as required to accommodate new
connection requests. The ZyXEL Device continues to delete half-open requests as necessary,
until the number of existing half-open sessions drops below another threshold (
max-
incomplete low
).
When the rate of new connection attempts rises above a threshold (
one-minute high
), the
ZyXEL Device starts deleting half-open sessions as required to accommodate new connection
requests. The ZyXEL Device continues to delete half-open sessions as necessary, until the rate
of new connection attempts drops below another threshold (
one-minute low
). The rate is the
number of new attempts detected in the last one-minute sample period.
10.10.2.1 TCP Maximum Incomplete and Blocking Time
An unusually high number of half-open sessions with the same destination host address could
indicate that a Denial of Service attack is being launched against the host.
Whenever the number of half-open sessions with the same destination host address rises above
a threshold (
TCP Maximum Incomplete
), the ZyXEL Device starts deleting half-open
sessions according to one of the following methods:
• If the
Blocking Time
timeout is 0 (the default), then the ZyXEL Device deletes the oldest
existing half-open session for the host for every new connection request to the host. This
ensures that the number of half-open sessions to a given host will never exceed the
threshold.
• If the
Blocking Time
timeout is greater than 0, then the ZyXEL Device blocks all new
connection requests to the host giving the server time to handle the present connections.
The ZyXEL Device continues to block all new connection requests until the
Blocking
Time
expires.
10.10.3 Configuring Firewall Thresholds
The ZyXEL Device also sends alerts whenever
TCP Maximum Incomplete
is exceeded. The
global values specified for the threshold and timeout apply to all TCP connections.
Click
Firewall
, and
Threshold
to bring up the next screen.
Summary of Contents for P-660HW-DX
Page 2: ......
Page 7: ...Safety Warnings P 660HW Dx User s Guide 7...
Page 8: ...Safety Warnings P 660HW Dx User s Guide 8...
Page 10: ...Contents Overview P 660HW Dx User s Guide 10...
Page 20: ...Table of Contents P 660HW Dx User s Guide 20...
Page 26: ...List of Figures P 660HW Dx User s Guide 26...
Page 31: ...31 PART I Introduction Introducing the ZyXEL Device 33 Introducing the Web Configurator 37...
Page 32: ...32...
Page 50: ...Chapter 2 Introducing the Web Configurator P 660HW Dx User s Guide 50...
Page 51: ...51 PART II Wizards Wizard Setup for Internet Access 53 Bandwidth Management Wizard 67...
Page 52: ...52...
Page 66: ...Chapter 3 Wizard Setup for Internet Access P 660HW Dx User s Guide 66...
Page 72: ...Chapter 4 Bandwidth Management Wizard P 660HW Dx User s Guide 72...
Page 74: ...74...
Page 92: ...Chapter 5 WAN Setup P 660HW Dx User s Guide 92...
Page 141: ...141 PART IV Security Firewalls 143 Firewall Configuration 155 Content Filtering 177...
Page 142: ...142...
Page 162: ...Chapter 10 Firewall Configuration P 660HW Dx User s Guide 162 Figure 88 Firewall Edit Rule...
Page 176: ...Chapter 10 Firewall Configuration P 660HW Dx User s Guide 176...
Page 180: ...Chapter 11 Content Filtering P 660HW Dx User s Guide 180...
Page 182: ...182...
Page 186: ...Chapter 12 Static Route P 660HW Dx User s Guide 186...
Page 202: ...Chapter 14 Dynamic DNS Setup P 660HW Dx User s Guide 202...
Page 224: ...Chapter 16 Universal Plug and Play UPnP P 660HW Dx User s Guide 224...
Page 226: ...226...
Page 232: ...Chapter 17 System P 660HW Dx User s Guide 232...
Page 250: ...Chapter 18 Logs P 660HW Dx User s Guide 250...
Page 256: ...Chapter 19 Tools P 660HW Dx User s Guide 256...
Page 264: ...264...
Page 330: ...Appendix F Internal SPTGEN P 660HW Dx User s Guide 330...
Page 332: ...Appendix G Command Interpreter P 660HW Dx User s Guide 332...
Page 344: ...Appendix J Splitters and Microfilters P 660HW Dx User s Guide 344...
Page 350: ...Appendix L Legal Information P 660HW Dx User s Guide 350...
Page 356: ...Appendix M Customer Support P 660HW Dx User s Guide 356...
Page 364: ...Index P 660HW Dx User s Guide 364...