
l
Session log: sent to the log server in real time.
l
Blacklist log: sent to the information center in real time.
l
Attack log and statistics log: sent to the information center periodically.
These logs help you find out security risks, detect attempts to violate security policies, and learn
the type of a network attack. The real-time log is also used to detect an intrusion that is underway.
Traffic Statistics and Monitoring
A firewall monitors data traffic and detects connection setup between internal and external
networks, generates statistics, and analyzes data. The firewall can analyze the logs by using
special software after events occur. The firewall also has analysis functions that enable it to
analyze data in real time.
By checking whether the number of TCP/UDP sessions initiated from external networks to the
internal network exceeds the threshold, the firewall determines whether to restrict new sessions
from external networks to the internal network or restrict new sessions from an IP address in the
internal network. If the firewall finds that the number of sessions in the system exceeds the
threshold, it speeds up the aging of sessions. This ensures that new sessions are set up. In this
way, a DoS attack can be prevented if the system is too busy.
shows an application of the firewall. The IP address-based statistics function is
enabled for the packets from external networks to the internal network. If the number of TCP
sessions initiated by external networks to Web server 129.9.0.1 exceeds the threshold, the
AR1200-S forbids external networks to initiate new sessions until the number of sessions is
smaller than the threshold.
Figure 3-1
Limiting the number of sessions initiated by external server
Ethernet
Internal
network
Web server
129.9.0.1
Router
TCP
connection
Internet
Attack Defense
With the attack defense feature, the AR1200-S can detect and protect against various network
attacks.
Network attacks are classified into three types: DoS attacks, scanning and snooping attacks, and
malformed packet attacks.
l
DoS attack
Denial of service (DoS) attack attacks a system with a large number of data packets. This
prevents the system from receiving requests from authorized users or suspends the host.
DoS attacks include SYN Flood attack and Fraggle attack. DoS attacks are different from
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
3 Firewall Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
47