Prestige 652 ADSL Security Router

Table 11-3 Attack Alert

FIELD

DESCRIPTION

DEFAULT VALUES

 

deletes half-open sessions as required to

half-open sessions rises above

 

accommodate new connection requests.

100, and to stop deleting half-

 

Do not set Maximum Incomplete High to

open sessions with the number

 

lower than the current Maximum

of existing half-open sessions

 

Incomplete Low number.

drops below 80.

TCP Maximum

This is the number of existing half-open

10 existing half-open TCP

Incomplete

TCP sessions with the same destination

sessions.

 

host IP address that causes the firewall to

 

 

start dropping half-open sessions to that

 

 

same destination host IP address. Enter a

 

 

number between 1 and 250. As a general

 

 

rule, you should choose a smaller number

 

 

for a smaller network, a slower system or

 

 

limited bandwidth.

 

 

 

 

Blocking Time

When TCP Maximum Incomplete is

10

 

reached you can choose if the next

minutes (default)

 

session should be allowed or blocked. If

 

 

you check Blocking Time any new

 

 

sessions will be blocked for the length of

 

 

time you specify in the next field (min) and

 

 

all old incomplete sessions will be cleared

 

 

during this period. If you want strong

 

 

security, it is better to block the

 

 

traffic for a short time, as it will give the

 

 

server some time to digest the loading.

 

(min)

Enter the length of Blocking Time in

0

 

minutes.

 

 

 

 

Click Back to return to the previous screen. Click Apply to save your customized settings and exit this screen. Click Reset to return to the previous configuration. Use the Help icon to view field descriptions.

11-10

Using the Prestige Web Configurator