3Com 3CRWE554G72T User Guide - Page 87

DoS Detect Criteria, System Tools - upgrade

Page 87 highlights

System Tools 87 System Tools DoS Detect Criteria 15 In the Total incomplete TCP/UDP sessions HIGH text box, enter the number of unestablished sessions that will cause the software to start deleting half-open sessions. The default is 300. 16 In the Total incomplete TCP/UDP sessions LOW text box, enter the number of unestablished sessions that must be reached before the software stops deleting half-open sessions. The default is 250. 17 In the Incomplete TCP/UDP sessions (per min) HIGH text box, enter the maximum number of incomplete TCP/UDP sessions allowed per minute. The default is 250 sessions. 18 In the Incomplete TCP/UDP sessions (per min) LOW text box, enter the minimum number of incomplete TCP/UDP sessions allowed per minute. The default is 200 sessions. 19 In the Maximum incomplete TCP/UDP sessions number from the same host text box, enter the maximum number of incomplete sessions allowed from the same host. The default is 10 sessions. 20 In the Incomplete TCP/UDP sessions detect sensitive time period text box, enter the length of time that must elapse before an incomplete TCP/UDP session is detected as incomplete. The default is 300 msec. 21 In the Maximum half-open fragmentation packet number from the same host text box, enter the maximum number of half-open fragmentation packets allowed from the same host. The default is 30 packets. 22 In the Half-open fragmentation detect sensitive time period text box, enter the length of time that must elapse before a half-open fragmentation session is detected as half-open. The default is 10000 msec. 23 In the Flooding cracker block time text box, enter the length of time that must elapse between detection of a flood attack and blocking the attack. The default is 300 seconds. Click Apply to save the settings. The main frame of the System Tools screen includes four administration items: Restart, Time Zone, Configuration, and Upgrade (Figure 66).

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146

System Tools
87
DoS Detect Criteria
15
In the
Total incomplete TCP/UDP sessions HIGH
text box, enter the
number of unestablished sessions that will cause the software to start
deleting half-open sessions. The default is 300.
16
In the
Total incomplete TCP/UDP sessions LOW
text box, enter the
number of unestablished sessions that must be reached before the
software stops deleting half-open sessions. The default is 250.
17
In the
Incomplete TCP/UDP sessions (per min) HIGH
text box, enter the
maximum number of incomplete TCP/UDP sessions allowed per minute.
The default is 250 sessions.
18
In the
Incomplete TCP/UDP sessions (per min) LOW
text box, enter the
minimum number of incomplete TCP/UDP sessions allowed per minute.
The default is 200 sessions.
19
In the
Maximum incomplete TCP/UDP sessions number from the same
host
text box, enter the maximum number of incomplete sessions
allowed from the same host. The default is 10 sessions.
20
In the
Incomplete TCP/UDP sessions detect sensitive time period
text box,
enter the length of time that must elapse before an incomplete TCP/UDP
session is detected as incomplete. The default is 300 msec.
21
In the
Maximum half-open fragmentation packet number from the same
host
text box, enter the maximum number of half-open fragmentation
packets allowed from the same host. The default is 30 packets.
22
In the
Half-open fragmentation detect sensitive time period
text box,
enter the length of time that must elapse before a half-open
fragmentation session is detected as half-open. The default is 10000
msec.
23
In the
Flooding cracker block time
text box, enter the length of time that
must elapse between detection of a flood attack and blocking the attack.
The default is 300 seconds.
Click
Apply
to save the settings.
System Tools
The main frame of the System Tools screen includes four administration
items:
Restart, Time Zone, Configuration,
and
Upgrade
(
Figure 66
).