P-662H/HW-D Series User’s Guide

Table 167 Firewall Commands (continued)

 

 

 

 

FUNCTION

COMMAND

DESCRIPTION

 

 

 

 

config edit firewall attack

This command sets the threshold rate of new

 

minute-high <0-255>

half-open sessions per minute where the

 

 

ZyXEL Device starts deleting old half-opened

 

 

sessions until it gets them down to the minute-

 

 

low threshold.

 

 

 

 

config edit firewall attack

This command sets the threshold of half-open

 

minute-low <0-255>

sessions where the ZyXEL Device stops

 

 

deleting half-opened sessions.

 

 

 

 

config edit firewall attack

This command sets the threshold of half-open

 

max-incomplete-high <0-255>

sessions where the ZyXEL Device starts

 

 

deleting old half-opened sessions until it gets

 

 

them down to the max incomplete low.

 

 

 

 

config edit firewall attack

This command sets the threshold where the

 

max-incomplete-low <0-255>

ZyXEL Device stops deleting half-opened

 

 

sessions.

 

 

 

 

config edit firewall attack

This command sets the threshold of half-open

 

tcp-max-incomplete <0-255>

TCP sessions with the same destination

 

 

where the ZyXEL Device starts dropping half-

 

 

open sessions to that destination.

 

 

 

Sets

config edit firewall set <set

This command sets a name to identify a

 

#> name <desired name>

specified set.

 

 

 

 

Config edit firewall set <set

This command sets whether a packet is

 

#> default-permit <forward

dropped or allowed through, when it does not

 

block>

meet a rule within the set.

 

 

 

 

Config edit firewall set <set

This command sets the time period to allow an

 

#> icmp-timeout <seconds>

ICMP session to wait for the ICMP response.

 

 

 

 

Config edit firewall set <set

This command sets how long a UDP

 

#> udp-idle-timeout <seconds>

connection is allowed to remain inactive

 

 

before the ZyXEL Device considers the

 

 

connection closed.

 

 

 

 

Config edit firewall set <set

This command sets how long ZyXEL Device

 

#> connection-timeout

waits for a TCP session to be established

 

<seconds>

before dropping the session.

 

 

 

 

Config edit firewall set <set

This command sets how long the ZyXEL

 

#> fin-wait-timeout <seconds>

Device leaves a TCP session open after the

 

 

firewall detects a FIN-exchange (indicating the

 

 

end of the TCP session).

Appendix K Firewall Commands

429