P-660HW-T v2 User’s Guide
Chapter 9 Firewalls
141
Under normal circumstances, the application that initiates a session sends a SYN
(synchronize) packet to the receiving server. The receiver sends back an ACK
(acknowledgment) packet and its own SYN, and then the initiator responds with an ACK
(acknowledgment). After this handshake, a connection is established.
•
SYN Attack
floods a targeted system with a series of SYN packets. Each packet causes
the targeted system to issue a SYN-ACK response. While the targeted system waits for
the ACK that follows the SYN-ACK, it queues up all outstanding SYN-ACK responses
on what is known as a backlog queue. SYN-ACKs are moved off the queue only when an
ACK comes back or when an internal timer (which is set at relatively long intervals)
terminates the three-way handshake. Once the queue is full, the system will ignore all
incoming SYN requests, making the system unavailable for legitimate users.
Figure 80
SYN Flood
• In a
LAND Attack
, hackers flood SYN packets into the network with a spoofed source
IP address of the targeted system. This makes it appear as if the host computer sent the
packets to itself, making the system unavailable while the target system tries to respond
to itself.
7
A
brute-force
attack, such as a "Smurf" attack, targets a feature in the IP specification
known as directed or subnet broadcasting, to quickly flood the target network with
useless data. A Smurf hacker floods a router with Internet Control Message Protocol
(ICMP) echo request packets (pings). Since the destination IP address of each packet is
the broadcast address of the network, the router will broadcast the ICMP echo request
packet to all hosts on the network. If there are numerous hosts, this will create a large
amount of ICMP echo request and response traffic. If a hacker chooses to spoof the
source IP address of the ICMP echo request packet, the resulting ICMP traffic will not
only clog up the "intermediary" network, but will also congest the network of the spoofed
source IP address, known as the "victim" network. This flood of broadcast traffic
consumes all available bandwidth, making communications impossible.
Summary of Contents for P-660HW-T - V2
Page 2: ......
Page 7: ...P 660HW T v2 User s Guide Safety Warnings 7 This product is recyclable Dispose of it properly...
Page 26: ...P 660HW T v2 User s Guide 26 List of Figures...
Page 40: ...P 660HW T v2 User s Guide 40 Chapter 1 Getting To Know Your ZyXEL Device...
Page 54: ...P 660HW T v2 User s Guide 54 Chapter 2 Introducing the Web Configurator...
Page 74: ...P 660HW T v2 User s Guide 74 Chapter 4 Bandwidth Management Wizard...
Page 92: ...P 660HW T v2 User s Guide 92 Chapter 5 WAN Setup...
Page 124: ...P 660HW T v2 User s Guide 124 Chapter 7 LAN Setup...
Page 156: ...P 660HW T v2 User s Guide 156 Chapter 10 Firewall Configuration Figure 85 Firewall Edit Rule...
Page 170: ...P 660HW T v2 User s Guide 170 Chapter 10 Firewall Configuration...
Page 174: ...P 660HW T v2 User s Guide 174 Chapter 11 Content Filtering...
Page 178: ...P 660HW T v2 User s Guide 178 Chapter 12 Static Route...
Page 190: ...P 660HW T v2 User s Guide 190 Chapter 13 Bandwidth Management...
Page 194: ...P 660HW T v2 User s Guide 194 Chapter 14 Dynamic DNS Setup...
Page 206: ...P 660HW T v2 User s Guide 206 Chapter 15 Remote Management Configuration...
Page 218: ...P 660HW T v2 User s Guide 218 Chapter 16 Universal Plug and Play UPnP...
Page 224: ...P 660HW T v2 User s Guide 224 Chapter 17 System...
Page 244: ...P 660HW T v2 User s Guide 244 Chapter 18 Logs...
Page 250: ...P 660HW T v2 User s Guide 250 Chapter 19 Tools...
Page 256: ...P 660HW T v2 User s Guide 256 Chapter 21 Troubleshooting...
Page 260: ...P 660HW T v2 User s Guide 260 Appendix A Product Specifications...
Page 280: ...P 660HW T v2 User s Guide 280 Appendix D Wall mounting Instructions...
Page 308: ...P 660HW T v2 User s Guide 308 Appendix G Command Interpreter...
Page 320: ...P 660HW T v2 User s Guide 320 Appendix J Splitters and Microfilters...
Page 334: ...P 660HW T v2 User s Guide 334 Appendix K Wireless LANs...