![Draytek Vigor IPPBX 2820n Скачать руководство пользователя страница 263](http://html1.mh-extra.com/html/draytek/vigor-ippbx-2820n/vigor-ippbx-2820n_user-manual_2529114263.webp)
VigorIPPBX 2820 Series User’s Guide
255
timeout are 50 packets per second and 10 seconds, respectively.
Enable PortScan
detection
Port Scan attacks the Vigor router by sending lots of packets to
many ports in an attempt to find ignorant services would
respond. Check the box to activate the Port Scan detection.
Whenever detecting this malicious exploration behavior by
monitoring the port-scanning Threshold rate, the Vigor router
will send out a warning. By default, the Vigor router sets the
threshold as 150 packets per second.
Block IP options
Check the box to activate the Block IP options function. The
Vigor router will ignore any IP packets with IP option field in
the datagram header. The reason for limitation is IP option
appears to be a vulnerability of the security for the LAN
because it will carry significant information, such as security,
TCC (closed user group) parameters, a series of Internet
addresses, routing messages...etc. An eavesdropper outside
might learn the details of your private networks.
Block Land
Check the box to enforce the Vigor router to defense the Land
attacks. The Land attack combines the SYN attack technology
with IP spoofing. A Land attack occurs when an attacker sends
spoofed SYN packets with the identical source and destination
addresses, as well as the port number to victims.
Block Smurf
Check the box to activate the Block Smurf function. The Vigor
router will ignore any broadcasting ICMP echo request.
Block trace router
Check the box to enforce the Vigor router not to forward any
trace route packets.
Block SYN fragment
Check the box to activate the Block SYN fragment function.
The Vigor router will drop any packets having SYN flag and
more fragment bit set.
Block Fraggle Attack
Check the box to activate the Block fraggle Attack function.
Any broadcast UDP packets received from the Internet is
blocked.
Activating the DoS/DDoS defense functionality might block
some legal packets. For example, when you activate the fraggle
attack defense, all broadcast UDP packets coming from the
Internet are blocked. Therefore, the RIP packets from the
Internet might be dropped.
Block TCP flag scan
Check the box to activate the Block TCP flag scan function.
Any TCP packet with anomaly flag setting is dropped. Those
scanning activities include
no flag scan
,
FIN without ACK scan
,
SYN FINscan
,
Xmas scan
and
full Xmas scan
.
Block Tear Drop
Check the box to activate the Block Tear Drop function. Many
machines may crash when receiving ICMP datagrams (packets)
that exceed the maximum length. To avoid this type of attack,
the Vigor router is designed to be capable of discarding any
fragmented ICMP packets with a length greater than 1024
octets.
Block Ping of Death
Check the box to activate the Block Ping of Death function.
This attack involves the perpetrator sending overlapping
packets to the target hosts so that those target hosts will hang
Содержание Vigor IPPBX 2820n
Страница 1: ......
Страница 2: ......
Страница 3: ...VigorIPPBX 2820 Series User s Guide Version 2 7 Based on Firmware Version V3 5 9 Date 10 12 2013...
Страница 25: ...VigorIPPBX 2820 Series User s Guide 17 Online status for Static IP for WAN1 Online status for DHCP WAN1...
Страница 28: ...VigorIPPBX 2820 Series User s Guide 20 This page is left blank...
Страница 196: ...VigorIPPBX 2820 Series User s Guide 188 This page is left blank...
Страница 245: ...VigorIPPBX 2820 Series User s Guide 237...
Страница 246: ...VigorIPPBX 2820 Series User s Guide 238...
Страница 362: ...VigorIPPBX 2820 Series User s Guide 354 Refresh Click it to reload the page...
Страница 370: ...VigorIPPBX 2820 Series User s Guide 362 This page is left blank...
Страница 375: ...VigorIPPBX 2820 Series User s Guide 367...