Firewall Setup
6-17
Click the checkbox to activate the Block TCP flag scan function. Any
TCP packet with anomaly flag setting is dropped. Those scanning
activities include
no flag scan
,
FIN without ACK scan
,
SYN FINscan
,
Xmas scan
and
full Xmas scan
.
Block Tear Drop
Click the checkbox to activate the Block Tear Drop function. Many
machines may crash when receiving ICMP datagrams (packets) that
exceed the maximum length. To avoid this type of attack, the Vigor
router is designed to be capable of discarding any fragmented ICMP
packets with a length greater than 1024 octets.
Block Ping of Death
Click the checkbox to activate the Block Ping of Death function. This
attack involves the perpetrator sending overlapping packets to the target
hosts so that those target hosts will hang once they re-construct the
packets. Any packets realizing this attacking activity will be blocked by
the Vigor routers.
Block ICMP Fragment
Click the checkbox to activate the Block ICMP fragment function. Any
ICMP packets with more fragment bit set are dropped.
Block Unknown Protocol
Click the checkbox to activate the Block Unknown Protocol function.
Individual IP packet has a protocol field in the datagram header to
indicate the protocol type running over the upper layer. However, the
protocol types greater than 100 are reserved and undefined at this time.
Therefore, the router should have ability to detect and reject this kind of
packets.
Содержание Vigor 2200V
Страница 1: ......
Страница 5: ...iv Preamble of DrayTek Vigor2200V series All Rights Reserved Hardware Connection ...
Страница 49: ...NAT Setup 5 9 ...
Страница 75: ...Firewall Setup 6 26 ...
Страница 108: ...VPN and Remote Access Setup 8 21 2 Create a LAN to LAN profile at Head Office ...
Страница 109: ...VPN and Remote Access Setup 8 22 3 Create a LAN to LAN profile at Branch Office ...