SMARTLINK
I&II
MDS921AE-10BTS - MDS
Level three, advanced, is an advanced level of firewall where user can determine the security level
for special purpose, environment, and applications by configuring the DoS protection and defining
an extra packet filter with higher priority than the default SPI filter. Note that, an improper filter
policy may degrade the capability of the firewall and/or even bl
The firewall security level can configure via
Packet Filtering
Packet filtering function can be configured by
and press enter.
>> active
Tigger packet
add
Add packet filtering rule
delete
Delete packet filtering rule
modify
Modify packet filtering rule
exchange
Exchange the filtering rule
list
Show packet filtering table
To enable the packet filtering function, you can use
Add the packet filtering rule via
>> protocol
Configure protocol type
direction
Configure direction mode
src_ip
Configure source IP parameter
dest_ip
Configure
port
Configure port parameter (TCP and UDP only)
tcp_flag
Configure TCP flag (TCP only)
icmp_type
Configure ICMP flag (ICMP only)
description
Packet filtering rule description
enable
Enable the packet filtering rule
begin
The schedule of beginning time
end
The schedule of ending time
action
Configure action mode
DoS Protection
DoS protection parameters can be configured in dos_protection menu. Move the cursor to
dos_protection
and press enter.
>> syn_flood
Enable protection SYN flood attack
icmp_flood
Enable protection ICMP flood attack
udp_flood
Enable protection UDP flood attack
ping_death
Enable protection ping of death attack
land_attack
Enable protection land attack
ip_spoff
Enable
smurf_attack
Enable protection smurf attack
fraggle_attack
Enable protection fraggle attack
A SYN flood attack attempts to slow your network by requesting new connections but not
completing the process to open the
full a server will not accept any more connections and will be unresponsive.
ICMP Flood: A sender transmits a volume of ICMP request packets to cause all CPU resources to
be consumed serving the phony requests.
S957AE-10BTS User Manual
Page 110 of 113
Level three, advanced, is an advanced level of firewall where user can determine the security level
al purpose, environment, and applications by configuring the DoS protection and defining
an extra packet filter with higher priority than the default SPI filter. Note that, an improper filter
policy may degrade the capability of the firewall and/or even block the normal network traffic.
The firewall security level can configure via
level
command.
Packet filtering function can be configured by
pkt_filter
command. Move the cursor to
Tigger packet filtering function
Add packet filtering rule
Delete packet filtering rule
Modify packet filtering rule
Exchange the filtering rule
Show packet filtering table
To enable the packet filtering function, you can use
active
command.
Add the packet filtering rule via
add
command.
Configure protocol type
Configure direction mode
Configure source IP parameter
Configure destination IP parameter
Configure port parameter (TCP and UDP only)
Configure TCP flag (TCP only)
Configure ICMP flag (ICMP only)
Packet filtering rule description
Enable the packet filtering rule
The schedule of beginning time
The schedule of ending time
Configure action mode
DoS protection parameters can be configured in dos_protection menu. Move the cursor to
and press enter.
Enable protection SYN flood attack
Enable protection ICMP flood attack
Enable protection UDP flood attack
Enable protection ping of death attack
Enable protection land attack
Enable protection IP spoofing attack
Enable protection smurf attack
Enable protection fraggle attack
A SYN flood attack attempts to slow your network by requesting new connections but not
completing the process to open the connection. Once the buffer for these pending connections is
full a server will not accept any more connections and will be unresponsive.
ICMP Flood: A sender transmits a volume of ICMP request packets to cause all CPU resources to
phony requests.
Level three, advanced, is an advanced level of firewall where user can determine the security level
al purpose, environment, and applications by configuring the DoS protection and defining
an extra packet filter with higher priority than the default SPI filter. Note that, an improper filter
ock the normal network traffic.
command. Move the cursor to
pkt_filter
DoS protection parameters can be configured in dos_protection menu. Move the cursor to
A SYN flood attack attempts to slow your network by requesting new connections but not
connection. Once the buffer for these pending connections is
ICMP Flood: A sender transmits a volume of ICMP request packets to cause all CPU resources to