Vigor130 Series User’s Guide
84
The default setting for threshold and timeout are 150 packets
per second and 10 seconds, respectively. That means, when
150 packets per second received, they will be regarded as
“attack event” and the session will be paused for 10
seconds.
Enable ICMP flood
defense
Check the box to activate the ICMP flood defense function.
Similar to the UDP flood defense function, once if the
Threshold of ICMP packets from Internet has exceeded the
defined value, the modem will discard the ICMP echo
requests coming from the Internet.
The default setting for threshold and timeout are 50 packets
per second and 10 seconds, respectively. That means, when
50 packets per second received, they will be regarded as
“attack event” and the session will be paused for 10
seconds.
Enable PortScan
detection
Port Scan attacks the Vigor modem by sending lots of
packets to many ports in an attempt to find ignorant services
would respond. Check the box to activate the Port Scan
detection. Whenever detecting this malicious exploration
behavior by monitoring the port-scanning Threshold rate,
the Vigor modem will send out a warning.
By default, the Vigor modem sets the threshold as 150
packets per second. That means, when 150 packets per
second received, they will be regarded as “attack event”.
Block IP options
Check the box to activate the Block IP options function.
The Vigor modem will ignore any IP packets with IP option
field in the datagram header. The reason for limitation is IP
option appears to be a vulnerability of the security for the
LAN because it will carry significant information, such as
security, TCC (closed user group) parameters, a series of
Internet addresses, routing messages...etc. An eavesdropper
outside might learn the details of your private networks.
Block Land
Check the box to enforce the Vigor modem to defense the
Land attacks. The Land attack combines the SYN attack
technology with IP spoofing. A Land attack occurs when an
attacker sends spoofed SYN packets with the identical
source and destination addresses, as well as the port number
to victims.
Block Smurf
Check the box to activate the Block Smurf function. The
Vigor modem will ignore any broadcasting ICMP echo
request.
Block trace router
Check the box to enforce the Vigor modem not to forward
any trace route packets.
Block SYN fragment
Check the box to activate the Block SYN fragment function.
The Vigor modem will drop any packets having SYN flag
and more fragment bit set.
Block Fraggle Attack
Check the box to activate the Block fraggle Attack function.
Any broadcast UDP packets received from the Internet is
blocked.
Содержание Vigor130
Страница 1: ...Vigor130 Series User s Guide i ...
Страница 10: ......
Страница 36: ...Vigor130 Series User s Guide 26 This page is left blank ...
Страница 51: ...Vigor130 Series User s Guide 41 ...
Страница 96: ...Vigor130 Series User s Guide 86 ...
Страница 156: ...Vigor130 Series User s Guide 146 This page is left blank ...
Страница 159: ...Vigor130 Series User s Guide 149 ...
Страница 160: ...Vigor130 Series User s Guide 150 This page is left blank ...
Страница 168: ...Vigor130 Series User s Guide 158 This page is left blank ...