SMC Networks SMC7904BRB2 manual DoS Criteria and Port Scan Criteria, High

Page 91

CONFIGURATION PARAMETERS

DoS Criteria and Port Scan Criteria

Set up DoS and port scan criteria in the spaces provided (as shown below).

Parameter

Defaults

Description

 

 

 

Total incomplete

300

Defines the rate of new unestablished sessions

TCP/UDP sessions

sessions

that will cause the software to start deleting

HIGH

 

half-open sessions.

Total incomplete

250

Defines the rate of new unestablished sessions

TCP/UDP sessions

sessions

that will cause the software to stop deleting half-

LOW

 

open sessions.

Incomplete

250

Maximum number of allowed incomplete

TCP/UDP sessions

sessions

TCP/UDP sessions per minute.

(per min) HIGH

 

 

Incomplete

200

Minimum number of allowed incomplete

TCP/UDP sessions

sessions

TCP/UDP sessions per minute.

(per min) LOW

 

 

Maximum incomplete

10

Maximum number of incomplete TCP/UDP

TCP/UDP sessions

 

sessions from the same host.

number from same

 

 

host

 

 

Incomplete

300

TCP/UDP sessions

msec

detect sensitive time

 

period

 

Maximum half-open

30

fragmentation packet

 

number from same

 

host

 

Half-open

10000

fragmentation detect

msec

sensitive time period

 

Flooding cracker

300

block time

second

Length of time before an incomplete TCP/UDP session is detected as incomplete.

Maximum number of half-open fragmentation packets from the same host.

Length of time before a half-open fragmentation session is detected as half-open.

Length of time from detecting a flood attack to blocking the attack.

Note: The firewall does not significantly affect system performance, so we advise enabling the prevention features to protect your network.

4-53

Image 91
Contents Page Page Router with built-in ADSL2/2+ Modem Trademarks Limited Warranty Limited Warranty Federal Communication Commission Interference Statement CompliancesEC Conformance Declaration Safety Compliance Wichtige Sicherheitshinweise Germany Compliances Table of Contents Configuring the BarricadeTM Vii Viii About the Barricade Features and BenefitsShared IP Address Wired LANInternet Access ApplicationsVirtual Private Network VPN Virtual ServerDMZ Host Support SecurityIntroduction Package Contents Chapter InstallationHardware Description System RequirementsSMC7904BRA2 Rear Panel SMC7904BRB2 Rear Panel SMC7904BRA2 Front Panel LED Indicators SMC7904BRA2SMC7904BRB2 Front Panel LED Indicators SMC7904BRB2Connect the System ISP SettingsConnect the Adsl Line Connect the Power Adapter Attach to Your Network Using Ethernet CablingConnection Illustration Installation TCP/IP Configuration Configuring Client PCDial-Up Connections WindowsProperties Obtain IP Settings from Your Barricade Disable Http ProxyAccessories/ Command Prompt Configuring Client PC Windows XP Obtain IP Settings from Your Barricade System Preferences Configuring Your Macintosh ComputerInternet Explorer Uncheck all check boxes and click OK Configuring Client PC Chapter Configuring Barricadetm Navigating the Management Interface Making Configuration Changes Time Zone Setup WizardParameter Setting Parameter Setting Country or ISP Not Listed Parameter Description PPPoEPPPoA Your ISP Bridging DhcpBridging Static Routing Bridging Routing Dhcp ISP ConfirmSetup Wizard Menu Description Configuration parametersDdns System Time SettingsPassword Settings Remote Management WAN ATM PVC Bridging ATM InterfacePPPoA Routing PPPoE IP Over RFC1483 bridged Clone MAC Address DNS LAN IP LANVlan Vlan Profile NAT Address Mapping Virtual Server Special Application NAT Mapping Table Static Route RoutingRIP This method provides very little security as it Routing Table Firewall Access Control Configuring the Barricadetm MAC Filter URL Blocking Schedule Rule Configuring the Barricadetm Intrusion Detection Intrusion Detection Feature Configuring the Barricadetm Stateful Packet Inspection Connection Policy Parameter Defaults DescriptionHigh DoS Criteria and Port Scan CriteriaDMZ Snmp Community Trap Upnp QOS Traffic Mapping Traffic Statistics Adsl Parameters AdslAdsl Status Error Interleaved Path Ddns Ping Utility ToolsTrace Route Utility Configuration Tools Firmware Upgrade Reset Status Configuring the Barricadetm Following items are included on the Status screen Linux Finding the MAC address of a Network CardWindows NT4/2000/XP MacintoshAppendix a Troubleshooting Hosts on the attached LAN. However, if you manually Troubleshooting Chart Troubleshooting Wiring Conventions SpecificationsEthernet Cable RJ-45 Port Connection Figure B-1. RJ-45 Ethernet Connector Pin NumbersPin Assignments Straight-Through WiringCrossover Wiring Adsl Cable Figure B-2. RJ-11 Connector Pin NumbersFigure B-3. RJ-11 Pinouts Management Features Physical Characteristics PortsAdsl Features ATM FeaturesWeight 500 g Input Power 12 V 1 a Ieee Standards Security FeaturesLAN Features Temperature IEC
Related manuals
Manual 2 pages 37.56 Kb