Billion Electric Company 7402VL user manual Intrusion Detection, Block Duration

Page 66
Intrusion Detection

VoIP/(802.11g) ADSL2+ Router

Intrusion Detection

The router’s Intrusion Detection System (IDS) is used to detect hacker attacks and intrusion attempts from the Internet. If the IDS function of the firewall is enabled, inbound packets are filtered and blocked depending on whether they are detected as possible hacker attacks, intrusion attempts or other connections that the router determines to be suspicious.

Blacklist: If the router detects a possible attack, the source IP or destination IP address will be added to the Blacklist. Any further attempts using this IP address will be blocked for the time period specified as the Block Duration. The default setting for this function is false (disabled). Some attack types are denied immediately without using the Blacklist function, such as Land attack and Echo/CharGen scan.

Intrusion Detection: If enabled, IDS will block Smurf attack attempts. Default is false.

Block Duration:

Victim Protection Block Duration: This is the duration for blocking Smurf attacks. Default value is 600 seconds.

Scan Attack Block Duration: This is the duration for blocking hosts that attempt a possible Scan attack. Scan attack types include X’mas scan, IMAP SYN/FIN scan and similar attempts. Default value is 86400 seconds.

DoS Attack Block Duration: This is the duration for blocking hosts that attempt a possible Denial of Service (DoS) attack. Possible DoS attacks this attempts to block include Ascend Kill and WinNuke. Default value is 1800 seconds.

Max TCP Open Handshaking Count: This is a threshold value to decide whether a SYN Flood attempt is occurring or not. Default value is 100 TCP SYN per seconds.

Max PING Count: This is a threshold value to decide whether an ICMP Echo Storm is occurring or not. Default value is 15 ICMP Echo Requests (PING) per second.

65

Chapter 4: Configuration

Image 66
Contents VoIP/802.11g ADSL2+ Router Version ReleaseBiPAC 7402VL/VGL/VGP User’s ManualCHAPTER 4 CONFIGURATION CHAPTER 2 INSTALLING THE ROUTERCHAPTER 3 BASIC INSTALLATION CHAPTER 1 INTRODUCTIONFirewall and Access Control CHAPTER 5 TROUBLESHOOTINGAPPENDIX A PRODUCT SUPPORT AND CONTACT INFORMATION QoS Quality of ServiceIntroduction to your Router FeaturesChapter 1 Introduction ModelsMulti-Protocol to Establish A Connection Quick Installation WizardQuality of Service QoS Universal Plug and Play UPnP and UPnP NAT TraversalRich Packet Filtering Dynamic Host Configuration Protocol DHCP client and serverFirmware Upgradeable Static and RIP1/2 RoutingPackage Contents Chapter 2 Installing the RouterImportant note for using this router Do not use the same power source for this router as other equipmentRJ-45 connector The Front LEDsMeaning RJ-11 connector7402VGL The Rear Ports7402VL 7402VGP8 Antenna 7402VGL/VGP only Port 1 Power Switch 2 PWR 3 RESET LAN 4 1X - 3X RJ-45 connector5 CONSOLE Phone 6 1X 2X RJ-11 connector 7 ADSL MeaningCabling Chapter 3 Basic Installation Chapter 3 Basic InstallationConnecting your router 7402VL/VGL7402VGP 2. Double-click Local Area Connection. See Figure Configuring PCs in Windows in Window XPFigure 3.3 TCP / IP Figure 3.4 IP Address & DNS Configuration 4. Select Internet Protocol TCP/IP and click Properties. See Figure2. Double-click Local Area “LAN” Connection. See Figure Configuring PCs in WindowsFigure 3.8 IP Address & DNS Configuration Figure 3.5 LAN Area ConnectionFigure 3.11 DNS Configuration Configuring PC in Windows 95/98/ME5. Then select the DNS Configuration tab. See Figure 3. Click Properties Figure 3.9 TCP / IPFigure 3.12 TCP / IP Configuring PC in Windows NT4.02. Select TCP/IP Protocol and click Properties. See Figure Figure 3.13 IP AddressLAN Device IP Settings Factory Default SettingsWeb Interface Username and Password ISP setting in WAN siteInformation from your ISP PPPoE PPPoA RFC1483 Bridged RFC1483 Routed IPoAConfiguring with your Web Browser Figure 3.14 User name & Password Prompt WidonwChapter 4 Configuration Quick Start ConfigurationSave Config to FLASH Wireless Association Table 7402VGL/VGP only StatusARP Table Routing Table Routing TableRIP Routing Table Expired Table DHCP TableLeased Table Permanent TableEmail Status VoIP StatusEvent Log Error Log NAT SessionsUPnP Portmap Quick Start Chapter 4 Configuration Configuration LAN Local Area NetworkEthernet Ethernet Client Filter Default setting is set to Disable Ethernet Client FilterActive PC in LAN displays a list of individual Ethernet device’s IP Address & MAC Address which connecting to the router Enable ParametersWireless Distribution System WDS WPA Pre-Shared Key Wireless Security 7402VGL/VGP onlyPage Wireless Client MAC Address Filter 7402VGL/VGP only →Associated Wireless ClientsAssociate Wireless Client displays a list of individual wireless device’s MAC Address that currently connects to the router DHCP Server WAN Wide Area Network RFC 1483 Routed Connections RFC 1483 Bridged Connections PppoePPPoA Routed Connections Connection Advanced Options PPPoAGive DNSto DHCP Server Similar to the above, but gives the DNS server address to the DHCP server IPoA Routed Connections PPPoE Connections Advanced Options PPPoE Chapter 4Configuration VoIP/802.11g ADSL2+ RouterPage ADSL System Time ZoneRemote Access Firmware Upgrade Backup / Restore Restart Router User Management Firewall and Access Control General Settings Packet Filter Application Example Predefined Port Filters RulesTable 1 Predefined Port Filter ProtocolPacket Filter - Add TCP/UDP Filter Packet Filter - Add Raw IP Filter Page Configuring Packet Filter Click DeleteClick Add TCP/UDP Filter 3. Click Add TCP/UDP Filter5. The new port filter rule for HTTP is shown below Intrusion Detection Block DurationDetect Parameter Table 2 Hacker attack types recognized by the IDSIntrusion Name Ascend KillURL Filter Domains Filtering This function checks the domain name only, not the IP address, in URLs accessed against your list of domains to block or allow. If it is matched, the URL request will be sent Trusted or dropped Forbidden. For this function to be activated, both check-boxes must be checked. The checking procedure is Restrict URL Features This function enhances the restriction to your URL rules Firewall Log Log information can be seen in the Status - Event Log after enablingVoIP Voice over Internet Protocol PSTN Dial PlanSetting for Phone Port Authentication Username Same as Phone NumberPlease refer to the description of “Setting for Phone Port 1” WizardGeneral Configuration SIP Device ParametersRegistrar Port from VoIP device Phone Configuration Login Account ConfigurationAuthentication Username Same as Phone Number Codec Preference Speed DialFor examples Action For ExampleDial without Prefix Dial only the Number of Digits and not the prefix SIP service is not available Power downInternet Service fail automaticallyFlash-hook OptionDescription 74xnumber#QoS Quality of Service Prioritization HighStandard DSCP Wireless ADSL RouterTable 4 DSCP Mapping Table DSCP Mapping TableOutbound IP Throttling LAN to WAN Inbound IP Throttling WAN to LAN Connection Diagram Example QoS for your NetworkVoIP Normal PCs Restricted Information and SettingsMission-critical application Voice applicationRestricted Application Advanced setting by using IP throttling Virtual Server “Port Forwarding” Add Virtual Server Application HTTPSever Time Schedule Always On Protocol tcp IP AddressEdit DMZ Host Edit One-to-One NAT Network Address Translation Global IP AddressSelect the Apply button to apply your changes Port Number Example List of some well-known and registered port numbersTable 5 Well-known and registered Ports ProtocolTime Schedule Click Edit Edit a Time SlotDelete a Time Slot Configuration of Time ScheduleAdvanced Static RouteDynamic DNS Check Email Device Management Embedded Web ServerSNMP V1 and SNMP Version SNMPv2c and SNMPv3Universal Plug and Play UPnP SNMPFrom RFC 1493 Bridge MIB From RFC 1213 MIB-IIFrom RFC1650 EtherLike-MIB From RFC 1471 PPP/LCP MIBFrom RFC1573 IfMIB From RFC 1473 PPP/IP MIBFrom RFC 1474 PPP/Bridge MIB From RFC1695 atmMIBIGMP Save Configuration to Flash Logout Problems with the WAN Interface Chapter 5 TroubleshootingProblems starting up the router ProblemProblems with the LAN Interface Can’t ping any PCs on the LANAPPENDIX A Product Support and Contact Information Contact Billion AUSTRALIAWORLDWIDE