Firewall
Session Settings Configuration
Cisco RV132W ADSL2+ Wireless-N and RV134W VDSL2 Wireless-AC VPN Router Administration Guide
101
5
•
ICMP Flood
: Enter the number of ICMP packets per second, including PING
packets, that will cause the security appliance to determine that an ICMP
flood intrusion event is occurring. Enter a value from 0 to 10000 ICMP
packets per second. The default value is 100 ICMP packets per seconds. A
value of zero (0) indicates that the ICMP Flood feature is disabled.
•
Block UDP Flood:
Check to prevent the security appliance from accepting
more than 150 simultaneous, active UDP connections per second from a
single computer on the LAN and enter a value from 0 -10000, default = 1000.
•
Block TCP Flood
: Check to drop all invalid TCP packets and enter a value
from 0 - 10000, default = 200. This feature protects your network from a SYN
flood attack, in which an attacker sends a succession of SYN (synchronize)
requests to a target system.
STEP 3
Click
Save
.
Session Settings Configuration
You can limit the maximum number of unidentified sessions and half-open
sessions on the Cisco RV132W/RV134W. You can also introduce timeouts for TCP
and UDP sessions to ensure Internet traffic is not deviating from expectations in
your private network.
To configure session settings:
STEP 1
Select
Firewall > Session Setting
.
STEP 2
In the
TCP Session Timeout
field, enter the time, in seconds, after which inactive
TCP sessions are removed from the session table. Most TCP sessions normally
terminate when the RST or FIN flags are detected. This value ranges from 18000
through 432000 seconds. The default is 86,400 seconds (24 hours).
STEP 3
In the
UDP Timeout
field, enter the time, in seconds, after which inactive UDP
sessions are removed from the session table. This value ranges from 90 through
360 seconds. The default is 180 seconds (3 minutes).
STEP 4
In the
ICMP Timeout
field, enter the time, in seconds, after which inactive ICMP
sessions are removed from the session table. This value ranges from 15 through
60 seconds. The default is 30 seconds.