ZyWALL 10 Internet Security Gateway

FIELD

DESCRIPTION

DEFAULT VALUES

 

rises above this number, the ZyWALL

half-open sessions when

 

deletes half-open sessions as required to

the number of existing

 

accommodate new connection requests.

half-open sessions rises

 

Do not set Maximum Incomplete High to

above 100, and to stop

 

lower than the current Maximum

deleting half-open

 

Incomplete Low number.

sessions with the number

 

 

of existing half-open

 

 

sessions drops below 80.

 

 

 

TCP Maximum

This is the number of existing half-open

10 existing half-open TCP

Incomplete

TCP sessions with the same destination

sessions.

 

host IP address that causes the firewall to

 

 

start dropping half-open sessions to that

 

 

same destination host IP address. Enter a

 

 

number between 1 and 250. As a general

 

 

rule, you should choose a smaller number

 

 

for a smaller network, a slower system or

 

 

limited bandwidth.

 

 

 

 

Blocking Time

When TCP Maximum Incomplete is

Check this checkbox to

 

reached you can choose if the next

specify a number in

 

session should be allowed or blocked. If

minutes (min) text box.

 

you check Blocking Time any new

 

 

sessions will be blocked for the length of

 

 

time you specify in the next field (min) and

 

 

all old incomplete sessions will be cleared

 

 

during this period. If you want strong

 

 

security, it is better to block the

 

 

traffic for a short time, as it will give the

 

 

server some time to digest the loading.

 

(min)

Enter the length of Blocking Time in

10

 

minutes.

 

 

 

 

When you have finished, click Apply to save your customized settings and exit this screen, Cancel to exit this screen without saving, or Help for online HTML help on fields in this screen.

Introducing the ZyWALL Web Configurator

15-11