Industrial 5-Port 10/100/1000T VPN Security Gateway
IVR-100
- 61 -
4.6.1 Firewall
A "Denial-of-Service" (DoS) attack is characterized by an explicit attempt by hackers to prevent
legitimate users of a service from using that service. The Gateway can prevent specific DoS attacks as
shown in
Figure 4-30
.
Figure 4-30:
Firewall
Object
Description
SPI Firewall
The SPI Firewall prevents attack and improper access to network
resources.
The default configuration is enabled.
Block SYN Flood
SYN Flood is a popular attack way. DoS and DDoS are TCP
protocols. Hackers like using this method to make a fake connection
that involves the CPU, memory, and so on.
The default configuration is enabled.
Block FIN Flood
If the function is enabled, when the number of the current FIN
packets is beyond the set value, the Gateway will start the blocking
function immediately.
The default configuration is disabled.