P-660HW-T v2 User’s Guide
166
Chapter 10 Firewall Configuration
The following table describes the labels in this screen.
10.10 DoS Thresholds
For DoS attacks, the ZyXEL Device uses thresholds to determine when to drop sessions that
do not become fully established. These thresholds apply globally to all sessions.
You can use the default threshold values, or you can change them to values more suitable to
your security requirements.
Refer to
Section 10.10.3 on page 168
to configure thresholds.
10.10.1 Threshold Values
Tune these parameters when something is not working and after you have checked the firewall
counters. These default values should work fine for most small offices. Factors influencing
choices for threshold values are:
• The maximum number of opened sessions.
• The minimum capacity of server backlog in your LAN network.
• The CPU power of servers in your LAN network.
• Network bandwidth.
• Type of traffic for certain servers.
Table 58
Firewall: Anti Probing
LABEL
DESCRIPTION
Respond to PING
on
The ZyXEL Device does not respond to any incoming Ping requests when
Disable
is selected.
Select
LAN
to reply to incoming LAN Ping requests.
Select
WAN
to reply to incoming WAN Ping requests.
Otherwise select
LAN & WAN
to reply to both incoming LAN and WAN Ping
requests.
Do Not Respond to
Requests for
Unauthorized
Services.
Select this option to prevent hackers from finding the ZyXEL Device by probing for
unused ports. If you select this option, the ZyXEL Device will not respond to port
request(s) for unused ports, thus leaving the unused ports and the ZyXEL Device
unseen. By default this option is not selected and the ZyXEL Device will reply with
an ICMP Port Unreachable packet for a port probe on its unused UDP ports, and a
TCP Reset packet for a port probe on its unused TCP ports.
Note that the probing packets must first traverse the ZyXEL Device's firewall
mechanism before reaching this anti-probing mechanism. Therefore if the firewall
mechanism blocks a probing packet, the ZyXEL Device reacts based on the
corresponding firewall policy to send a TCP reset packet for a blocked TCP packet
or an ICMP port-unreachable packet for a blocked UDP packets or just drop the
packets without sending a response packet.
Apply
Click
Apply
to save your changes to the ZyXEL Device.
Cancel
Click
Cancel
to begin configuring this screen afresh.
Summary of Contents for P-660HW-T - V2
Page 2: ......
Page 7: ...P 660HW T v2 User s Guide Safety Warnings 7 This product is recyclable Dispose of it properly...
Page 26: ...P 660HW T v2 User s Guide 26 List of Figures...
Page 40: ...P 660HW T v2 User s Guide 40 Chapter 1 Getting To Know Your ZyXEL Device...
Page 54: ...P 660HW T v2 User s Guide 54 Chapter 2 Introducing the Web Configurator...
Page 74: ...P 660HW T v2 User s Guide 74 Chapter 4 Bandwidth Management Wizard...
Page 92: ...P 660HW T v2 User s Guide 92 Chapter 5 WAN Setup...
Page 124: ...P 660HW T v2 User s Guide 124 Chapter 7 LAN Setup...
Page 156: ...P 660HW T v2 User s Guide 156 Chapter 10 Firewall Configuration Figure 85 Firewall Edit Rule...
Page 170: ...P 660HW T v2 User s Guide 170 Chapter 10 Firewall Configuration...
Page 174: ...P 660HW T v2 User s Guide 174 Chapter 11 Content Filtering...
Page 178: ...P 660HW T v2 User s Guide 178 Chapter 12 Static Route...
Page 190: ...P 660HW T v2 User s Guide 190 Chapter 13 Bandwidth Management...
Page 194: ...P 660HW T v2 User s Guide 194 Chapter 14 Dynamic DNS Setup...
Page 206: ...P 660HW T v2 User s Guide 206 Chapter 15 Remote Management Configuration...
Page 218: ...P 660HW T v2 User s Guide 218 Chapter 16 Universal Plug and Play UPnP...
Page 224: ...P 660HW T v2 User s Guide 224 Chapter 17 System...
Page 244: ...P 660HW T v2 User s Guide 244 Chapter 18 Logs...
Page 250: ...P 660HW T v2 User s Guide 250 Chapter 19 Tools...
Page 256: ...P 660HW T v2 User s Guide 256 Chapter 21 Troubleshooting...
Page 260: ...P 660HW T v2 User s Guide 260 Appendix A Product Specifications...
Page 280: ...P 660HW T v2 User s Guide 280 Appendix D Wall mounting Instructions...
Page 308: ...P 660HW T v2 User s Guide 308 Appendix G Command Interpreter...
Page 320: ...P 660HW T v2 User s Guide 320 Appendix J Splitters and Microfilters...
Page 334: ...P 660HW T v2 User s Guide 334 Appendix K Wireless LANs...