Chapter 10 Firewall Configuration
P-660HW-Dx v2 User’s Guide
172
The following table describes the labels in this screen.
10.10 DoS Thresholds
For DoS attacks, the ZyXEL Device uses thresholds to determine when to drop sessions that
do not become fully established. These thresholds apply globally to all sessions.
You can use the default threshold values, or you can change them to values more suitable to
your security requirements.
Refer to
to configure thresholds.
10.10.1 Threshold Values
Tune these parameters when something is not working and after you have checked the firewall
counters. These default values should work fine for most small offices. Factors influencing
choices for threshold values are:
• The maximum number of opened sessions.
• The minimum capacity of server backlog in your LAN network.
• The CPU power of servers in your LAN network.
• Network bandwidth.
• Type of traffic for certain servers.
If your network is slower than average for any of these factors (especially if you have servers
that are slow or handle many tasks and are often busy), then the default values should be
reduced.
You should make any changes to the threshold values before you continue configuring
firewall rules.
Table 62
Firewall: Anti Probing
LABEL
DESCRIPTION
Respond to PING
on
The ZyXEL Device does not respond to any incoming Ping requests when
Disable
is selected.
Select
LAN
to reply to incoming LAN Ping requests.
Select
WAN
to reply to incoming WAN Ping requests.
Otherwise select
LAN & WAN
to reply to both incoming LAN and WAN Ping
requests.
Do Not Respond
to Requests for
Unauthorized
Services.
Select this option to prevent hackers from finding the ZyXEL Device by probing for
unused ports. If you select this option, the ZyXEL Device will not respond to port
request(s) for unused ports, thus leaving the unused ports and the ZyXEL Device
unseen. By default this option is not selected and the ZyXEL Device will reply with
an ICMP Port Unreachable packet for a port probe on its unused UDP ports, and a
TCP Reset packet for a port probe on its unused TCP ports.
Note that the probing packets must first traverse the ZyXEL Device's firewall
mechanism before reaching this anti-probing mechanism. Therefore if the firewall
mechanism blocks a probing packet, the ZyXEL Device reacts based on the
corresponding firewall policy to send a TCP reset packet for a blocked TCP
packet or an ICMP port-unreachable packet for a blocked UDP packets or just
drop the packets without sending a response packet.
Apply
Click
Apply
to save your changes to the ZyXEL Device.
Cancel
Click
Cancel
to begin configuring this screen afresh.
Содержание P-660HW-D1 V2
Страница 2: ......
Страница 7: ...Safety Warnings P 660HW Dx v2 User s Guide 7...
Страница 8: ...Safety Warnings P 660HW Dx v2 User s Guide 8...
Страница 10: ...Contents Overview P 660HW Dx v2 User s Guide 10...
Страница 19: ...Table of Contents P 660HW Dx v2 User s Guide 19 Index 351...
Страница 20: ...Table of Contents P 660HW Dx v2 User s Guide 20...
Страница 26: ...List of Figures P 660HW Dx v2 User s Guide 26...
Страница 31: ...31 PART I Introduction Introducing the ZyXEL Device 33 Introducing the Web Configurator 39...
Страница 32: ...32...
Страница 51: ...51 PART II Wizards Wizard Setup for Internet Access 53 Bandwidth Management Wizard 67...
Страница 52: ...52...
Страница 66: ...Chapter 3 Wizard Setup for Internet Access P 660HW Dx v2 User s Guide 66...
Страница 72: ...Chapter 4 Bandwidth Management Wizard P 660HW Dx v2 User s Guide 72...
Страница 73: ...73 PART III Network WAN Setup 75 LAN Setup 93 Wireless LAN 105 Network Address Translation NAT Screens 129...
Страница 74: ...74...
Страница 92: ...Chapter 5 WAN Setup P 660HW Dx v2 User s Guide 92...
Страница 128: ...Chapter 7 Wireless LAN P 660HW Dx v2 User s Guide 128...
Страница 141: ...141 PART IV Security Firewalls 143 Firewall Configuration 155 Content Filtering 177 Certificates 145...
Страница 142: ...142...
Страница 162: ...Chapter 10 Firewall Configuration P 660HW Dx v2 User s Guide 162 Figure 92 Firewall Edit Rule...
Страница 176: ...Chapter 10 Firewall Configuration P 660HW Dx v2 User s Guide 176...
Страница 180: ...Chapter 11 Content Filtering P 660HW Dx v2 User s Guide 180...
Страница 182: ...182...
Страница 186: ...Chapter 12 Static Route P 660HW Dx v2 User s Guide 186...
Страница 202: ...Chapter 14 Dynamic DNS Setup P 660HW Dx v2 User s Guide 202...
Страница 224: ...Chapter 16 Universal Plug and Play UPnP P 660HW Dx v2 User s Guide 224...
Страница 225: ...225 PART VI Maintenance and Troubleshooting System 227 Logs 233 Tools 251 Diagnostic 257 Troubleshooting 259...
Страница 226: ...226...
Страница 232: ...Chapter 17 System P 660HW Dx v2 User s Guide 232...
Страница 250: ...Chapter 18 Logs P 660HW Dx v2 User s Guide 250...
Страница 256: ...Chapter 19 Tools P 660HW Dx v2 User s Guide 256...
Страница 264: ...264...
Страница 332: ...Appendix F Internal SPTGEN P 660HW Dx v2 User s Guide 332...
Страница 346: ...Appendix J Legal Information P 660HW Dx v2 User s Guide 346...
Страница 358: ...Index P 660HW Dx v2 User s Guide 358...