67
DSL-504T User’s Manual
D-Link Systems, Inc.
Advanced - Firewall
Advanced-Firewall (continued)
When DoS, Port Scan, or Service Filtering Protection is enabled, it will create a firewall
policy to protect your network against the following:
Dos Protection
SYN Flood check
ICMP Redirection
check
Port Scan Protection
Nmap/FIN attack
URG/PSH attack
Xmas Tree Scan
Null Scan attack
SYN/RST attack
SYN/FIN Scan
Service Filtering
Ping from WAN
Telnet from WAN
FTP from WAN
DNS from WAN
IKE from WAN
RIP from WAN
DHCP from WAN
A DoS “denial-of-service” attack is characterized by an explicit attempt by attackers to
prevent legitimate users of a service from using that service. Examples include: attempts
to “flood” a network, thereby preventing legitimate network traffic, attempts to disrupt
connections between two machines, thereby preventing access to a service, attempts
to prevent a particular individual from accessing a service, or, attempts to disrupt service
to a specific system or person.
Port scan protection is designed to block attempts to discover vulnerable ports or services
that might be exploited in an attack from the WAN.
The Service Filtering options allow you to block FTP, Telnet response, Pings, etc, from
the external network. Check the category you want to block to enable filtering of that
type of packet.
When you have selected the desired Firewall policies, click the Apply button to enforce
the policies. Remember to save any configuration changes.