. . . . .
A T T A C K D E T E C T I O N A N D P R E V E N T I O N
Configuring the freeGuard Blaze 2100 to Defend Against DoS and DDoS Attacks
Version 3R2
Security Appliance User Guide
5-7
CONFIGURING ICMP FLOOD PREVENTION
To configure the rate limit for ICMP traffic for a specific zone, use the
set
zone
command with the
icmp-flood attack-threshold
option. This
enables you to set limits (per second) on the number of ICMP packets
allowed through that zone to a specific host.
set zone {zone name} screen icmp-flood attack-threshold
{number}
E X A M P L E : S E T T I N G T H E I C M P T H R E S H O L D
Set the ICMP threshold to
1,000
on the untrust zone:
set zone untrust screen icmp-flood attack-threshold 1000
save
G U I E X A M P L E : S E T T I N G T H E I C M P T H R E S H O L D
1
Policy > Attack Settings Edit Zone (for “unturst”)
2
Enter the following, then click
Apply
:
ICMP flood attack threshold: 1000
CONFIGURING UDP FLOOD PREVENTION
To configure the rate limit for UDP datagrams in a specific zone, use the
set zone
command with the
udp-flood attack-threshold
option:
set zone {zone name} screen udp-flood attack-threshold
{number}
This sets a rate limit for the number of UDP datagrams allowed through
the zone to a specific host per second. The maximum threshold for the
udp-flood attack-threshold
is 64,000.
CONFIGURING SYN FLOOD PREVENTION
A host or multiple hosts that sends a large number of invalid SYN packets
can overwhelm network devices. This causes network devices to allocate
more resources to process the invalid SYN requests, leaving fewer
resources available to process legitimate traffic requests. If you apply
rate limits to restrict the number of SYN packets allowed through a zone,
the appliance detects and protects against SYN flood attacks.
Содержание freeGuard Blaze 2100
Страница 1: ...freeGuard Blaze 2100 User Guide Version 3R2...
Страница 14: ...I NT R O DU C T I O N About Document Conventions 1 4 Security Appliance User Guide Version 3R2 1...
Страница 24: ...G E T T IN G S T A R T E D Installing the freeGuard Blaze 2100 2 10 Security Appliance User Guide Version 3R2 2...
Страница 82: ...SY ST EM MA N AGEM E N T Using Traceroute 4 22 Security Appliance User Guide Version 3R2 4...
Страница 192: ...P OL IC Y CO NF I G URA T IO N About Schedules 9 28 Security Appliance User Guide Version 3R2 9...
Страница 216: ...P R E DEF I N E D SER V IC ES A 4 Security Appliance User Guide Version 3R2 A...