ZyWALL 5/35/70 Series User’s Guide

Table 271 Firewall Commands (continued)

 

 

 

 

FUNCTION

COMMAND

DESCRIPTION

 

 

 

 

config edit firewall attack

This command sets the threshold rate of new

 

minute-high <0-255>

half-open sessions per minute where the

 

 

ZyWALL starts deleting old half-opened

 

 

sessions until it gets them down to the minute-

 

 

low threshold.

 

 

 

 

config edit firewall attack

This command sets the threshold of half-open

 

minute-low <0-255>

sessions where the ZyWALL stops deleting

 

 

half-opened sessions.

 

 

 

 

config edit firewall attack

This command sets the threshold of half-open

 

max-incomplete-high <0-255>

sessions where the ZyWALL starts deleting

 

 

old half-opened sessions until it gets them

 

 

down to the max incomplete low.

 

 

 

 

config edit firewall attack

This command sets the threshold where the

 

max-incomplete-low <0-255>

ZyWALL stops deleting half-opened sessions.

 

 

 

 

config edit firewall attack

This command sets the threshold of half-open

 

tcp-max-incomplete <0-255>

TCP sessions with the same destination

 

 

where the ZyWALL starts dropping half-open

 

 

sessions to that destination.

 

 

 

Sets

config edit firewall set <set

This command sets a name to identify a

 

#> name <desired name>

specified set.

 

 

 

 

Config edit firewall set <set

This command sets whether a packet is

 

#> default-permit <forward

dropped or allowed through, when it does not

 

block>

meet a rule within the set.

 

 

 

 

Config edit firewall set <set

This command sets the time period to allow an

 

#> icmp-timeout <seconds>

ICMP session to wait for the ICMP response.

 

 

 

 

Config edit firewall set <set

This command sets how long a UDP

 

#> udp-idle-timeout <seconds>

connection is allowed to remain inactive

 

 

before the ZyWALL considers the connection

 

 

closed.

 

 

 

 

Config edit firewall set <set

This command sets how long ZyWALL waits

 

#> connection-timeout

for a TCP session to be established before

 

<seconds>

dropping the session.

 

 

 

 

Config edit firewall set <set

This command sets how long the ZyWALL

 

#> fin-wait-timeout <seconds>

leaves a TCP session open after the firewall

 

 

detects a FIN-exchange (indicating the end of

 

 

the TCP session).

 

 

 

Appendix N Firewall Commands

754