ZyXEL LTE7485-S905 User Guide - Page 126

DoS, Select Service, TCP/UDP, ICMPv6, Reject, Accept, WAN to LAN, WAN to Router

Page 126 highlights

Chapter 11 Firewall Table 46 Security > Firewall > Access Control > Add New ACL Rule (continued) LABEL DESCRIPTION IP Type Select between IPv4 or IPv6. Compared to IPv4, IPv6 (Internet Protocol version 6), is designed to enhance IP address size and features. The increase in IPv6 address size to 128 bits (from the 32-bit IPv4 address) allows up to 3.4 x 1038 IP addresses. The Zyxel Device can use IPv4/IPv6 dual stack to connect to IPv4 and IPv6 networks, and supports IPv6 rapid deployment (6RD). Select Service Select a service from the Select Service box. Protocol Select the protocol (ALL, TCP/UDP, TCP, UDP, ICMP, or ICMPv6) used to transport the packets for which you want to apply the rule. Custom Source Port This is a single port number or the starting port number of a range that defines your rule. Custom Destination Port This is a single port number or the ending port number of a range that defines your rule. TCP Flag Select the TCP Flag (SYN, ACK, URG, PSH, RST, FIN). Policy Use the drop-down list box to select whether to discard (Drop), deny and send an ICMP destination-unreachable message to the sender (Reject), or allow the passage of (Accept) packets that match this rule. Direction Select WAN to LAN to apply the rule to traffic from WAN to LAN. Select LAN to WAN to apply the rule to traffic from LAN to WAN. Select WAN to Router to apply the rule to traffic from WAN to router. Select LAN to Router to apply the rule to traffic from LAN to router. Enable Rate Limit Click to enable (switch turns blue) the setting of maximum number of packets per maximum number of minute/second to limit the throughput of traffic that matches this rule. If not, the next item will be disabled. Scheduler Rules packet(s) per (1-512) Enter the maximum number of packets (1-512) per minute/second. Add New Rule Select a schedule rule for this ACL rule from the drop-down list box. You can configure a new schedule rule by clicking Add New Rule. OK Click this to save your changes. Cancel Click this to exit this screen without saving. 11.6 DoS DoS (Denial of Service) attacks can flood your Internet connection with invalid packets and connection requests, using so much bandwidth and so many resources that Internet access becomes unavailable. Use the DoS screen to activate protection against DoS attacks. Click Security > Firewall > DoS to display the following screen. Figure 97 Security > Firewall > DoS LTE Series User's Guide 126

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210

Chapter 11 Firewall
LTE Series User’s Guide
126
11.6
DoS
DoS (Denial of Service) attacks can flood your Internet connection with invalid packets and connection
requests, using so much bandwidth and so many resources that Internet access becomes unavailable.
Use the
DoS
screen to activate protection against DoS attacks.
Click
Security > Firewall > DoS
to display the following screen.
Figure 97
Security > Firewall > DoS
IP Type
Select between
IPv4
or
IPv6
. Compared to
IPv4
,
IPv6
(Internet Protocol version 6), is
designed to enhance IP address size and features. The increase in
IPv6
address size to
128 bits (from the 32-bit
IPv4
address) allows up to 3.4 x 1038 IP addresses. The Zyxel
Device can use
IPv4
/
IPv6
dual stack to connect to
IPv4
and
IPv6
networks, and supports
IPv6
rapid deployment (6RD).
Select Service
Select a service from the
Select Service
box.
Protocol
Select the protocol (
ALL
,
TCP/UDP
,
TCP
,
UDP
,
ICMP
, or
ICMPv6
) used to transport the
packets for which you want to apply the rule.
Custom Source Port
This is a single port number or the starting port number of a range that defines your rule.
Custom Destination
Port
This is a single port number or the ending port number of a range that defines your rule.
TCP Flag
Select the TCP Flag (SYN, ACK, URG, PSH, RST, FIN).
Policy
Use the drop-down list box to select whether to discard (
Drop
), deny
and send an ICMP
destination-unreachable message to the sender (
Reject
), or allow the passage of
(
Accept
) packets that match this rule.
Direction
Select
WAN to LAN
to apply the rule to traffic from WAN to LAN. Select
LAN to WAN
to
apply the rule to traffic from LAN to WAN. Select
WAN to Router
to apply the rule to traffic
from WAN to router. Select
LAN to Router
to apply the rule to traffic from LAN to router.
Enable Rate Limit
Click to enable (switch turns blue) the setting of maximum number of packets per
maximum number of minute/second to limit the throughput of traffic that matches this
rule. If not, the next item will be disabled.
Scheduler Rules
packet(s) per (1-512)
Enter the maximum number of
packets (1-512) per minute
/
second
.
Add New Rule
Select a schedule rule for this ACL rule from the drop-down list box. You can configure a
new schedule rule by clicking
Add New Rule
.
OK
Click this to save your changes.
Cancel
Click this to exit this screen without saving.
Table 46
Security > Firewall > Access Control > Add New ACL Rule (continued)
LABEL
DESCRIPTION