ZyWALL 10/50 Internet Security Gateway

Table 12-3 Attack Alert

FIELD

DESCRIPTION

DEFAULT VALUES

 

 

 

Denial of Service Thresholds

 

 

 

 

One Minute Low

This is the rate of new half-open sessions

80 existing half-open sessions.

 

that causes the firewall to stop deleting

 

 

half-open sessions. The ZyWALL

 

 

continues to delete half-open sessions as

 

 

necessary, until the rate of new

 

 

connection attempts drops below this

 

 

number.

 

One Minute High

This is the rate of new half-open sessions

100 half-open sessions per

 

that causes the firewall to start deleting

minute. The above numbers

 

half-open sessions. When the rate of new

cause the ZyWALL to start

 

connection attempts rises above this

deleting half-open sessions

 

number, the ZyWALL deletes half-open

when more than 100 session

 

sessions as required to accommodate

establishment attempts have

 

new connection attempts.

been detected in the last minute,

 

 

and to stop deleting half-open

 

 

sessions when fewer than 80

 

 

session establishment attempts

 

 

have been detected in the last

 

 

minute.

 

 

 

Maximum Incomplete

This is the number of existing half-open

80 existing half-open sessions.

Low

sessions that causes the firewall to stop

 

 

deleting half-open sessions. The ZyWALL

 

 

continues to delete half-open requests as

 

 

necessary, until the number of existing

 

 

half-open sessions drops below this

 

 

number.

 

 

 

 

Maximum Incomplete

This is the number of existing half-open

100 half-open sessions per

High

sessions that causes the firewall to start

minute. The above values

 

deleting half-open sessions. When the

causes the ZyWALL to start

 

number of existing half-open sessions

deleting half-open sessions

 

rises above this number, the ZyWALL

when the number of existing

 

deletes half-open sessions as required to

half-open sessions rises above

 

accommodate new connection requests.

100, and to stop deleting half-

 

Do not set Maximum Incomplete High to

open sessions with the number

 

lower than the current Maximum

of existing half-open sessions

 

Incomplete Low number.

drops below 80.

TCP Maximum

This is the number of existing half-open

10 existing half-open TCP

Incomplete

TCP sessions with the same destination

sessions.

Using the ZyWALL Web Configurator

12-9