P-2602H(W)(L)-DxA Series User’s Guide
You should make any changes to the threshold values before you continue configuring firewall rules.
14.8.2 Half-Open Sessions
An unusually high number of
The ZyXEL Device measures both the total number of existing
When the number of existing
When the rate of new connection attempts rises above a threshold
14.8.2.1 TCP Maximum Incomplete and Blocking Time
An unusually high number of
Whenever the number of
athreshold (TCP Maximum Incomplete), the ZyXEL Device starts deleting
•If the Blocking Time timeout is 0 (the default), then the ZyXEL Device deletes the oldest existing
•If the Blocking Time timeout is greater than 0, then the ZyXEL Device blocks all new connection requests to the host giving the server time to handle the present connections. The ZyXEL Device continues to block all new connection requests until the Blocking Time expires.
208 | Chapter 14 Firewall Configuration |