
Chapter 11 Firewall
ZyWALL 2WG User’s Guide
263
The following table describes the labels in this screen.
Table 73
SECURITY > FIREWALL > Threshold
LABEL
DESCRIPTION
Disable DoS Attack
Protection on
Select the check boxes of any interfaces (or all VPN tunnels) for which you want
the ZyWALL to not use the Denial of Service protection thresholds. This disables
DoS protection on the selected interface (or all VPN tunnels).
You may want to disable DoS protection for an interface if the ZyWALL is treating
valid traffic as DoS attacks. Another option would be to raise the thresholds.
Denial of Service
Thresholds
The ZyWALL measures both the total number of existing half-open sessions and
the rate of session establishment attempts. Both TCP and UDP half-open
sessions are counted in the total number and rate measurements. Measurements
are made once a minute.
One Minute Low
This is the rate of new half-open sessions per minute that causes the firewall to
stop deleting half-open sessions. The ZyWALL continues to delete half-open
sessions as necessary, until the rate of new connection attempts drops below this
number.
One Minute High
This is the rate of new half-open sessions per minute that causes the firewall to
start deleting half-open sessions. When the rate of new connection attempts rises
above this number, the ZyWALL deletes half-open sessions as required to
accommodate new connection attempts.
For example, if you set the one minute high to 100, the ZyWALL starts deleting
half-open sessions when more than 100 session establishment attempts have
been detected in the last minute. It stops deleting half-open sessions when the
number of session establishment attempts detected in a minute goes below the
number set as the one minute low.
Maximum
Incomplete Low
This is the number of existing half-open sessions that causes the firewall to stop
deleting half-open sessions. The ZyWALL continues to delete half-open requests
as necessary, until the number of existing half-open sessions drops below this
number.
Maximum
Incomplete High
This is the number of existing half-open sessions that causes the firewall to start
deleting half-open sessions. When the number of existing half-open sessions
rises above this number, the ZyWALL deletes half-open sessions as required to
accommodate new connection requests. Do not set
Maximum Incomplete High
to lower than the current
Maximum Incomplete
Low
number.
For example, if you set the maximum incomplete high to 100, the ZyWALL starts
deleting half-open sessions when the number of existing half-open sessions rises
above 100. It stops deleting half-open sessions when the number of existing half-
open sessions drops below the number set as the maximum incomplete low.
TCP Maximum
Incomplete
An unusually high number of half-open sessions with the same destination host
address could indicate that a DoS attack is being launched against the host.
Specify the number of existing half-open TCP sessions with the same destination
host IP address that causes the firewall to start dropping half-open sessions to
that same destination host IP address. Enter a number between 1 and 256. As a
general rule, you should choose a smaller number for a smaller network, a slower
system or limited bandwidth. The ZyWALL sends alerts whenever the
TCP
Maximum Incomplete
is exceeded.
Action taken when
TCP Maximum
Incomplete
reached threshold
Select the action that ZyWALL should take when the TCP maximum incomplete
threshold is reached. You can have the ZyWALL either:
Delete the oldest half open session when a new connection request comes.
or
Deny new connection requests for the number of minutes that you specify
(between 1 and 256).
Apply
Click
Apply
to save your changes back to the ZyWALL.
Reset Click
Reset
to begin configuring this screen afresh.
Содержание ZYWALL 2 WG
Страница 1: ...www zyxel com ZyWALL 2WG Internet Security Appliance User s Guide Version 4 03 12 2007 Edition 1 ...
Страница 2: ......
Страница 8: ...Safety Warnings ZyWALL 2WG User s Guide 8 ...
Страница 42: ...List of Figures ZyWALL 2WG User s Guide 42 ...
Страница 50: ...List of Tables ZyWALL 2WG User s Guide 50 ...
Страница 52: ...52 ...
Страница 80: ...Chapter 2 Introducing the Web Configurator ZyWALL 2WG User s Guide 80 ...
Страница 100: ...Chapter 3 Wizard Setup ZyWALL 2WG User s Guide 100 ...
Страница 140: ...Chapter 4 Tutorial ZyWALL 2WG User s Guide 140 ...
Страница 145: ...145 PART II Network and Wireless LAN Screens 147 Bridge Screens 159 WAN Screens 165 DMZ Screens 201 Wireless LAN 211 ...
Страница 146: ...146 ...
Страница 158: ...Chapter 6 LAN Screens ZyWALL 2WG User s Guide 158 ...
Страница 171: ...Chapter 8 WAN Screens ZyWALL 2WG User s Guide 171 Figure 108 NETWORK WAN General ...
Страница 200: ...Chapter 8 WAN Screens ZyWALL 2WG User s Guide 200 ...
Страница 238: ...238 ...
Страница 258: ...Chapter 11 Firewall ZyWALL 2WG User s Guide 258 Figure 159 SECURITY FIREWALL Rule Summary Edit ...
Страница 270: ...Chapter 11 Firewall ZyWALL 2WG User s Guide 270 Figure 170 My Service Firewall Rule Example Rule Summary Completed ...
Страница 300: ...Chapter 13 Content Filtering Reports ZyWALL 2WG User s Guide 300 ...
Страница 313: ...Chapter 14 IPSec VPN ZyWALL 2WG User s Guide 313 Figure 199 SECURITY VPN VPN Rules IKE Edit Gateway Policy ...
Страница 322: ...Chapter 14 IPSec VPN ZyWALL 2WG User s Guide 322 Figure 202 SECURITY VPN VPN Rules IKE Edit Network Policy ...
Страница 348: ...Chapter 14 IPSec VPN ZyWALL 2WG User s Guide 348 ...
Страница 360: ...Chapter 15 Certificates ZyWALL 2WG User s Guide 360 Figure 229 SECURITY CERTIFICATES My Certificates Create Basic ...
Страница 378: ...Chapter 15 Certificates ZyWALL 2WG User s Guide 378 ...
Страница 380: ...Chapter 16 Authentication Server ZyWALL 2WG User s Guide 380 Figure 239 SECURITY AUTH SERVER Local User Database ...
Страница 384: ...384 ...
Страница 426: ...Chapter 20 Bandwidth Management ZyWALL 2WG User s Guide 426 ...
Страница 479: ...479 PART V Logs and Maintenance Logs Screens 481 Maintenance 511 ...
Страница 480: ...480 ...
Страница 485: ...Chapter 26 Logs Screens ZyWALL 2WG User s Guide 485 Figure 304 LOGS Log Settings ...
Страница 510: ...Chapter 26 Logs Screens ZyWALL 2WG User s Guide 510 ...
Страница 530: ...530 ...
Страница 558: ...Chapter 30 WAN and Dial Backup Setup ZyWALL 2WG User s Guide 558 ...
Страница 564: ...Chapter 31 LAN Setup ZyWALL 2WG User s Guide 564 ...
Страница 570: ...Chapter 32 Internet Access ZyWALL 2WG User s Guide 570 ...
Страница 574: ...Chapter 33 DMZ Setup ZyWALL 2WG User s Guide 574 ...
Страница 578: ...Chapter 34 Route Setup ZyWALL 2WG User s Guide 578 ...
Страница 582: ...Chapter 35 Wireless Setup ZyWALL 2WG User s Guide 582 ...
Страница 594: ...Chapter 37 IP Static Route Setup ZyWALL 2WG User s Guide 594 ...
Страница 614: ...Chapter 38 Network Address Translation NAT ZyWALL 2WG User s Guide 614 ...
Страница 632: ...Chapter 40 Filter Configuration ZyWALL 2WG User s Guide 632 ...
Страница 668: ...Chapter 44 System Maintenance Menus 8 to 10 ZyWALL 2WG User s Guide 668 ...
Страница 672: ...Chapter 45 Remote Management ZyWALL 2WG User s Guide 672 ...
Страница 680: ...Chapter 46 IP Policy Routing ZyWALL 2WG User s Guide 680 ...
Страница 685: ...685 PART VII Troubleshooting and Specifications Troubleshooting 687 Product Specifications 693 ...
Страница 686: ...686 ...
Страница 692: ...Chapter 48 Troubleshooting ZyWALL 2WG User s Guide 692 ...
Страница 702: ...Chapter 49 Product Specifications ZyWALL 2WG User s Guide 702 ...
Страница 704: ...704 ...
Страница 712: ...Appendix A Pop up Windows JavaScripts and Java Permissions ZyWALL 2WG User s Guide 712 ...
Страница 740: ...Appendix D Common Services ZyWALL 2WG User s Guide 740 ...
Страница 768: ...Appendix G Legal Information ZyWALL 2WG User s Guide 768 ...
Страница 774: ...Appendix H Customer Support ZyWALL 2WG User s Guide 774 ...