![Draytek Vigor2762 series Скачать руководство пользователя страница 243](http://html.mh-extra.com/html/draytek/vigor2762-series/vigor2762-series_user-manual_2529364243.webp)
Stateful Packet
Stateful Packet
Inspection (
Inspection (
SPI)
SPI)
Stateful inspection is a firewall architecture that works at the network layer. Unlike legacy
static packet filtering, which examines a packet based on the information in its header,
stateful inspection builds up a state machine to track each connection traversing all
interfaces of the firewall and makes sure they are valid. The stateful firewall of Vigor router
not only examines the header information also monitors the state of the connection.
Denial of
Denial of
Service (
Service (
DoS) Defense
DoS) Defense
The
DoS Defense
functionality helps you to detect and mitigate the DoS attack. The attacks
are usually categorized into two types, the flooding-type attacks and the vulnerability
attacks. The flooding-type attacks will attempt to exhaust all your system's resource while
the vulnerability attacks will try to paralyze the system by offending the vulnerabilities of
the protocol or operation system.
The
DoS Defense
function enables the Vigor router to inspect every incoming packet based
on the attack signature database. Any malicious packet that might duplicate itself to
paralyze the host in the secure LAN will be strictly blocked and a Syslog message will be
sent as warning, if you set up Syslog server.
Also the Vigor router monitors the traffic. Any abnormal traffic flow violating the pre-
defined parameter, such as the number of thresholds, is identified as an attack and the
Vigor router will activate its defense mechanism to mitigate in a real-time manner.
The below shows the attack types that DoS/DDoS defense function can detect:
1. SYN flood attack
2. UDP flood attack
3. ICMP flood attack
4. Port Scan attack
5. IP options
6. Land attack
7. Smurf attack
8. Trace route
9. SYN fragment
10. Fraggle attack
11. TCP flag scan
12. Tear drop attack
13. Ping of Death attack
14. ICMP fragment
15. Unassigned Numbers
Vigor2762 Series User’s Guide
233
Содержание Vigor2762 series
Страница 1: ......
Страница 135: ...Vigor2762 Series User s Guide 125 ...
Страница 201: ...This page is left blank Vigor2762 Series User s Guide 191 ...
Страница 261: ...Vigor2762 Series User s Guide 251 ...
Страница 311: ...Vigor2762 Series User s Guide 301 ...
Страница 326: ...Vigor2762 Series User s Guide 316 ...
Страница 330: ...Vigor2762 Series User s Guide 320 ...
Страница 353: ...11 Click OK to save the settings The class rules for WAN1 are defined as shown below Vigor2762 Series User s Guide 343 ...
Страница 408: ...This page is left blank Vigor2762 Series User s Guide 398 ...
Страница 435: ...Vigor2762 Series User s Guide 425 ...
Страница 444: ...Vigor2762 Series User s Guide 434 ...
Страница 448: ...Vigor2762 Series User s Guide 438 ...
Страница 450: ...Part IX DrayTek Tools Part IX DrayTek Tools Vigor2762 Series User s Guide 440 ...
Страница 455: ...This page is left blank Vigor2762 Series User s Guide 445 ...
Страница 456: ...Part X Telnet Commands Part X Telnet Commands Vigor2762 Series User s Guide 446 ...
Страница 505: ... minimum address of the pool FF02 1 1st DNS IPv6 Addr FF02 1 Vigor2762 Series User s Guide 495 ...
Страница 553: ... scr Vigor2762 Series User s Guide 543 ...
Страница 607: ...Vigor2762 Series User s Guide 597 ...
Страница 622: ...Vigor2762 Series User s Guide 612 ...