Chapter 10 Firewall Configuration
P-660HW-Dx v2 User’s Guide
173
10.10.2 Half-Open Sessions
An unusually high number of half-open sessions (either an absolute number or measured as
the arrival rate) could indicate that a Denial of Service attack is occurring. For TCP, "half-
open" means that the session has not reached the established state-the TCP three-way
handshake has not yet been completed (see
). For UDP, "half-open"
means that the firewall has detected no return traffic.
The ZyXEL Device measures both the total number of existing half-open sessions and the rate
of session establishment attempts. Both TCP and UDP half-open sessions are counted in the
total number and rate measurements. Measurements are made once a minute.
When the number of existing half-open sessions rises above a threshold (
max-incomplete
high
), the ZyXEL Device starts deleting half-open sessions as required to accommodate new
connection requests. The ZyXEL Device continues to delete half-open requests as necessary,
until the number of existing half-open sessions drops below another threshold (
max-
incomplete low
).
When the rate of new connection attempts rises above a threshold (
one-minute high
), the
ZyXEL Device starts deleting half-open sessions as required to accommodate new connection
requests. The ZyXEL Device continues to delete half-open sessions as necessary, until the rate
of new connection attempts drops below another threshold (
one-minute low
). The rate is the
number of new attempts detected in the last one-minute sample period.
10.10.2.1 TCP Maximum Incomplete and Blocking Time
An unusually high number of half-open sessions with the same destination host address could
indicate that a Denial of Service attack is being launched against the host.
Whenever the number of half-open sessions with the same destination host address rises above
a threshold (
TCP Maximum Incomplete
), the ZyXEL Device starts deleting half-open
sessions according to one of the following methods:
• If the
Blocking Time
timeout is 0 (the default), then the ZyXEL Device deletes the oldest
existing half-open session for the host for every new connection request to the host. This
ensures that the number of half-open sessions to a given host will never exceed the
threshold.
• If the
Blocking Time
timeout is greater than 0, then the ZyXEL Device blocks all new
connection requests to the host giving the server time to handle the present connections.
The ZyXEL Device continues to block all new connection requests until the
Blocking
Time
expires.
10.10.3 Configuring Firewall Thresholds
The ZyXEL Device also sends alerts whenever
TCP Maximum Incomplete
is exceeded. The
global values specified for the threshold and timeout apply to all TCP connections.
Click
Firewall
, and
Threshold
to bring up the next screen.
Содержание P-660HW-D1 V2
Страница 2: ......
Страница 7: ...Safety Warnings P 660HW Dx v2 User s Guide 7...
Страница 8: ...Safety Warnings P 660HW Dx v2 User s Guide 8...
Страница 10: ...Contents Overview P 660HW Dx v2 User s Guide 10...
Страница 19: ...Table of Contents P 660HW Dx v2 User s Guide 19 Index 351...
Страница 20: ...Table of Contents P 660HW Dx v2 User s Guide 20...
Страница 26: ...List of Figures P 660HW Dx v2 User s Guide 26...
Страница 31: ...31 PART I Introduction Introducing the ZyXEL Device 33 Introducing the Web Configurator 39...
Страница 32: ...32...
Страница 51: ...51 PART II Wizards Wizard Setup for Internet Access 53 Bandwidth Management Wizard 67...
Страница 52: ...52...
Страница 66: ...Chapter 3 Wizard Setup for Internet Access P 660HW Dx v2 User s Guide 66...
Страница 72: ...Chapter 4 Bandwidth Management Wizard P 660HW Dx v2 User s Guide 72...
Страница 73: ...73 PART III Network WAN Setup 75 LAN Setup 93 Wireless LAN 105 Network Address Translation NAT Screens 129...
Страница 74: ...74...
Страница 92: ...Chapter 5 WAN Setup P 660HW Dx v2 User s Guide 92...
Страница 128: ...Chapter 7 Wireless LAN P 660HW Dx v2 User s Guide 128...
Страница 141: ...141 PART IV Security Firewalls 143 Firewall Configuration 155 Content Filtering 177 Certificates 145...
Страница 142: ...142...
Страница 162: ...Chapter 10 Firewall Configuration P 660HW Dx v2 User s Guide 162 Figure 92 Firewall Edit Rule...
Страница 176: ...Chapter 10 Firewall Configuration P 660HW Dx v2 User s Guide 176...
Страница 180: ...Chapter 11 Content Filtering P 660HW Dx v2 User s Guide 180...
Страница 182: ...182...
Страница 186: ...Chapter 12 Static Route P 660HW Dx v2 User s Guide 186...
Страница 202: ...Chapter 14 Dynamic DNS Setup P 660HW Dx v2 User s Guide 202...
Страница 224: ...Chapter 16 Universal Plug and Play UPnP P 660HW Dx v2 User s Guide 224...
Страница 225: ...225 PART VI Maintenance and Troubleshooting System 227 Logs 233 Tools 251 Diagnostic 257 Troubleshooting 259...
Страница 226: ...226...
Страница 232: ...Chapter 17 System P 660HW Dx v2 User s Guide 232...
Страница 250: ...Chapter 18 Logs P 660HW Dx v2 User s Guide 250...
Страница 256: ...Chapter 19 Tools P 660HW Dx v2 User s Guide 256...
Страница 264: ...264...
Страница 332: ...Appendix F Internal SPTGEN P 660HW Dx v2 User s Guide 332...
Страница 346: ...Appendix J Legal Information P 660HW Dx v2 User s Guide 346...
Страница 358: ...Index P 660HW Dx v2 User s Guide 358...