
Chapter 11 Firewalls
P-2802H(W)(L)-I Series User’s Guide
171
Figure 97
Firewall Example: Rules: MyService
11.8 Firewall Thresholds
For DoS
attacks, the ZyXEL Device uses thresholds to determine when to start dropping
sessions that do not become fully established (half-open sessions). These thresholds apply
globally to all sessions.
For TCP, half-open means that the session has not reached the established state-the TCP three-
way handshake has not yet been completed. Under normal circumstances, the application that
initiates a session sends a SYN (synchronize) packet to the receiving server. The receiver
sends back an ACK (acknowledgment) packet and its own SYN, and then the initiator
responds with an ACK (acknowledgment). After this handshake, a connection is established.
Figure 98
Three-Way Handshake
For UDP, half-open means that the firewall has detected no return traffic. An unusually high
number (or arrival rate) of half-open sessions could indicate a DOS attack.
Содержание P-2802H-I Series
Страница 1: ...www zyxel com P 2802H W L I Series VDSL VoIP IAD User s Guide Version 3 70 6 2007 Edition 1...
Страница 2: ......
Страница 7: ...Safety Warnings P 2802H W L I Series User s Guide 7...
Страница 8: ...Safety Warnings P 2802H W L I Series User s Guide 8...
Страница 10: ...Contents Overview P 2802H W L I Series User s Guide 10...
Страница 32: ...List of Tables P 2802H W L I Series User s Guide 32...
Страница 33: ...33 PART I Introduction Introducing the ZyXEL Device 35 Introducing the Web Configurator 43...
Страница 34: ...34...
Страница 50: ...Chapter 2 Introducing the Web Configurator P 2802H W L I Series User s Guide 50...
Страница 51: ...51 PART II Wizard Internet and Wireless Setup Wizard 53 VoIP Wizard And Example 65...
Страница 52: ...52...
Страница 64: ...Chapter 3 Internet and Wireless Setup Wizard P 2802H W L I Series User s Guide 64...
Страница 70: ...Chapter 4 VoIP Wizard And Example P 2802H W L I Series User s Guide 70...
Страница 72: ...72...
Страница 82: ...Chapter 5 Status Screens P 2802H W L I Series User s Guide 82...
Страница 88: ...Chapter 6 WAN Setup P 2802H W L I Series User s Guide 88...
Страница 116: ...Chapter 8 Wireless LAN P 2802H W L I Series User s Guide 116...
Страница 154: ...Chapter 10 Voice P 2802H W L I Series User s Guide 154...
Страница 174: ...Chapter 11 Firewalls P 2802H W L I Series User s Guide 174...
Страница 178: ...Chapter 12 Content Filtering P 2802H W L I Series User s Guide 178...
Страница 184: ...Chapter 13 Introduction to IPSec P 2802H W L I Series User s Guide 184...
Страница 219: ...Chapter 15 Certificates P 2802H W L I Series User s Guide 219 Figure 122 My Certificate Details...
Страница 238: ...Chapter 16 Static Route P 2802H W L I Series User s Guide 238...
Страница 250: ...Chapter 17 Quality of Service QoS P 2802H W L I Series User s Guide 250...
Страница 254: ...Chapter 18 Dynamic DNS Setup P 2802H W L I Series User s Guide 254...
Страница 282: ...Chapter 20 Universal Plug and Play UPnP P 2802H W L I Series User s Guide 282...
Страница 284: ...284...
Страница 324: ...Chapter 25 Troubleshooting P 2802H W L I Series User s Guide 324...
Страница 334: ...Chapter 26 Product Specifications P 2802H W L I Series User s Guide 334...
Страница 336: ...336...
Страница 348: ...Appendix A Setting up Your Computer s IP Address P 2802H W L I Series User s Guide 348...
Страница 404: ...Appendix G Legal Information P 2802H W L I Series User s Guide 404...
Страница 410: ...Appendix H Customer Support P 2802H W L I Series User s Guide 410...
Страница 418: ...Index P 2802H W L I Series User s Guide 418...