Table 67 Firewall: Threshold (continued)
LABEL | DESCRIPTION | DEFAULT VALUES |
|
|
|
Maximum | This is the number of existing | 80 existing |
Incomplete Low | sessions that causes the firewall to stop |
|
| deleting |
|
| Device continues to delete |
|
| as necessary, until the number of existing |
|
|
| |
Maximum | This is the number of existing | 100 existing |
Incomplete High | sessions that causes the firewall to start | The above values causes the |
| deleting | ZyXEL Device to start deleting half- |
| number of existing | open sessions when the number of |
| above this number, the ZyXEL Device deletes | existing |
| above 100, and to stop deleting | |
| accommodate new connection requests. Do | |
| not set Maximum Incomplete High to lower | number of existing |
| than the current Maximum Incomplete Low | sessions drops below 80. |
| number. |
|
TCP Maximum | This is the number of existing | 30 existing |
Incomplete | sessions with the same destination host IP | sessions. |
| address that causes the firewall to start |
|
| dropping |
|
| destination host IP address. Enter a number |
|
| between 1 and 256. As a general rule, you |
|
| should choose a smaller number for a smaller |
|
| network, a slower system or limited |
|
| bandwidth. |
|
Action taken when the TCP Maximum Incomplete threshold is reached. | ||
|
|
|
Delete the oldest | Select this radio button to clear the oldest half |
|
half open session | open session when a new connection request |
|
when new | comes. |
|
connection |
|
|
request comes |
|
|
Deny new | Select this radio button and specify for how |
|
connection | long the ZyXEL Device should block new |
|
request for | connection requests when TCP Maximum |
|
| Incomplete is reached. |
|
| Enter the length of blocking time in minutes |
|
| (between 1 and 256). |
|
Apply | Click Apply to save your changes back to the ZyXEL Device. | |
|
| |
Cancel | Click Cancel to begin configuring this screen afresh. | |
|
|
|
178 | Chapter 9 Firewall Configuration |