ZyXEL VES1724-56B2 User Guide - Page 287

Table 128, Label, Description

Page 287 highlights

Chapter 31 DoS Prevention The following table describes the labels in this screen. Table 128 DoS Prevention LABEL Active Action Mac IP ICMP TCP UDP Apply Cancel DESCRIPTION Select the check box to enable DoS prevention. Specify the action(s) and filtering criteria the Switch takes on all incoming packets. Select the If packets with source Mac address equals destination Mac address, drop them. check box to discard any packets whose source MAC address and destination MAC address are the same. Select the If packets with source IP address equals destination IP address, drop them. check box to discard any IP packets whose source IP address and destination IP address are the same. select the If the packets are fragmented ICMP packets, drop them. check box to have the Switch discard any fragmented ICMP packets. Select the Check TCP SYN packet with source port values are always 0, drop them. check box to have the Switch discard any TCP SYN packets whose source port numbers are zero. Select the TCP fragments with offset value of 1 are dropped. check box to have the Switch discard any TCP fragments with a Data Offset of 1. Select the TCP packets with control flags equals 0 and sequence number equals 0, drop them. check box to have the Switch discard any TCP packets whose control (flag) bit and sequence number are 0. Select the TCP packets with source port equals destination port, drop them. check box to have the Switch discard any TCP packets whose source port and destination port are the same. Select the TCP packets with SYN and FIN bits, drop them. check box to have the Switch discard the TCP packets that contain both SYN (SYNchronize) and FIN (Finish) flags. Select the TCP packets with FIN, URG and PSH bits and sequence number equals 0, drop them. check box to have the Switch discard any TCP packets whose FIN (Finish), URG (URGent) and PSH (Push) flags bits and sequence number are 0. Select the UDP packets with source port equals destination port, drop them. check box to have the Switch discard any UDP packets whose source port and destination port are the same. Click Apply to save your changes to the Switch's run-time memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click Cancel to begin configuring this screen afresh. VES1724-56 User's Guide 287

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414

Chapter 31 DoS Prevention
VES1724-56 User’s Guide
287
The following table describes the labels in this screen.
Table 128
DoS Prevention
LABEL
DESCRIPTION
Active
Select the check box to enable DoS prevention.
Action
Specify the action(s) and filtering criteria the Switch takes on all incoming packets.
Mac
Select the
If packets with source Mac address equals destination Mac address, drop
them.
check box to discard any packets whose source MAC address and destination MAC
address are the same.
IP
Select the
If packets with source IP address equals destination IP address, drop
them.
check box to discard any IP packets whose source IP address and destination IP
address are the same.
ICMP
select the
If the packets are fragmented ICMP packets, drop them.
check box to have
the Switch discard any fragmented ICMP packets.
TCP
Select the
Check TCP SYN packet with source port values are always 0, drop them.
check box to have the Switch discard any TCP SYN packets whose source port numbers are
zero.
Select the
TCP fragments with offset value of 1 are dropped.
check box to have the
Switch discard any TCP fragments with a Data Offset of 1.
Select the
TCP packets with control flags equals 0 and sequence number equals 0,
drop them.
check box to have the Switch discard any TCP packets whose control (flag) bit
and sequence number are 0.
Select the
TCP packets with source port equals destination port, drop them.
check
box to have the Switch discard any TCP packets whose source port and destination port are
the same.
Select the
TCP packets with SYN and FIN bits, drop them.
check box to have the Switch
discard the TCP packets that contain both SYN (SYNchronize) and FIN (Finish) flags.
Select the
TCP packets with FIN, URG and PSH bits and sequence number equals 0,
drop them.
check box to have the Switch discard any TCP packets whose FIN (Finish), URG
(URGent) and PSH (Push) flags bits and sequence number are 0.
UDP
Select the
UDP packets with source port equals destination port, drop them.
check
box to have the Switch discard any UDP packets whose source port and destination port are
the same.
Apply
Click
Apply
to save your changes to the Switch’s run-time memory. The Switch loses these
changes if it is turned off or loses power, so use the
Save
link on the top navigation panel to
save your changes to the non-volatile memory when you are done configuring.
Cancel
Click
Cancel
to begin configuring this screen afresh.