ZyWALL P1 User’s Guide
120
Chapter 7 Firewall Screens
7.10.1 Threshold Values
Tune these parameters when something is not working and after you have checked the firewall
counters. These default values should work fine for normal small offices with ADSL
bandwidth. Factors influencing choices for threshold values are:
1
The maximum number of opened sessions.
2
The minimum capacity of server backlog in your LAN network.
3
The CPU power of servers in your LAN network.
4
Network bandwidth.
5
Type of traffic for certain servers.
If your network is slower than average for any of these factors (especially if you have servers
that are slow or handle many tasks and are often busy), then the default values should be
reduced.
You should make any changes to the threshold values before you continue configuring
firewall rules.
7.10.2 Half-Open Sessions
For TCP, half-open means that the session has not reached the established state-the TCP three-
way handshake has not yet been completed (see
). For UDP, half-open
means that the firewall has detected no return traffic. An unusually high number of half-open
sessions (either an absolute number or measured as the arrival rate) could indicate that a
Denial of Service attack is occurring.
The ZyWALL measures both the total number of existing half-open sessions and the rate of
session establishment attempts. Both TCP and UDP half-open sessions are counted in the total
number and rate measurements. Measurements are made once a minute.
When the number of existing half-open sessions rises above a threshold (
max-incomplete
high
), the ZyWALL starts deleting half-open sessions as required to accommodate new
connection requests. The ZyWALL continues to delete half-open requests as necessary, until
the number of existing half-open sessions drops below another threshold (
max-incomplete
low
).
When the rate of new connection attempts rises above a threshold (
one-minute high
), the
ZyWALL starts deleting half-open sessions as required to accommodate new connection
requests. The ZyWALL continues to delete half-open sessions as necessary, until the rate of
new connection attempts drops below another threshold (
one-minute low
). The rate is the
number of new attempts detected in the last one-minute sample period.
7.10.2.1 TCP Maximum Incomplete and Blocking Time
An unusually high number of half-open sessions with the same destination host address could
indicate that a Denial of Service attack is being launched against the host.
Содержание ZyXEL ZyWALL P1
Страница 1: ...ZyWALL P1 Internet Security Appliance User s Guide Version 3 64 8 2005...
Страница 9: ...ZyWALL P1 User s Guide 8 Customer Support...
Страница 25: ...ZyWALL P1 User s Guide 24 List of Figures...
Страница 39: ...ZyWALL P1 User s Guide 38 Chapter 1 Getting to Know Your ZyWALL...
Страница 51: ...ZyWALL P1 User s Guide 50 Chapter 2 Introducing the Web Configurator...
Страница 72: ...ZyWALL P1 User s Guide Chapter 3 Wizard Setup 71 Figure 22 VPN Wizard Complete...
Страница 73: ...ZyWALL P1 User s Guide 72 Chapter 3 Wizard Setup...
Страница 91: ...ZyWALL P1 User s Guide 90 Chapter 5 WAN Screens...
Страница 116: ...ZyWALL P1 User s Guide Chapter 7 Firewall Screens 115 Figure 44 Firewall Example My Service Rule Configuration...
Страница 129: ...ZyWALL P1 User s Guide 128 Chapter 8 Introduction to IPSec...
Страница 151: ...ZyWALL P1 User s Guide 150 Chapter 9 VPN Screens...
Страница 191: ...ZyWALL P1 User s Guide 190 Chapter 12 Static Route...
Страница 215: ...ZyWALL P1 User s Guide 214 Chapter 13 Remote Management...
Страница 248: ...ZyWALL P1 User s Guide Chapter 16 Maintenance 247 Figure 134 Restart Screen...
Страница 249: ...ZyWALL P1 User s Guide 248 Chapter 16 Maintenance...
Страница 269: ...ZyWALL P1 User s Guide 268 Chapter 18 Troubleshooting...
Страница 289: ...ZyWALL P1 User s Guide 288 Appendix B IP Subnetting...
Страница 295: ...ZyWALL P1 User s Guide 294 Appendix D PPTP...
Страница 299: ...ZyWALL P1 User s Guide 298 Appendix E Triangle Route...
Страница 329: ...ZyWALL P1 User s Guide 328 Appendix H Importing Certificates...
Страница 331: ...ZyWALL P1 User s Guide 330 Appendix I Command Interpreter...
Страница 337: ...ZyWALL P1 User s Guide 336 Appendix J Firewall Commands...
Страница 341: ...ZyWALL P1 User s Guide 340 Appendix K NetBIOS Filter Commands...
Страница 347: ...ZyWALL P1 User s Guide 346 Appendix M Brute Force Password Guessing Protection...
Страница 369: ...ZyWALL P1 User s Guide 368 Index X X Auth 132 Z ZyNOS 250 ZyXEL Limited Warranty Note 4 ZyXEL s Firewall Introduction 92...