D-Link DFL-2500 User Guide - Page 315

Limitations, Setting Up Zone Defense

Page 315 highlights

296 Chapter 28. Zone Defense adding the firewall's interface IP or MAC address connecting towards the Zone Defense switch to the Exclude list. This prevents the firewall from being accidentally blocked out. 28.5 Limitations Depending on the switch model, various limitations are in effect. The first one is the latency between the triggering of a block rule to the moment of the switch(es) actually blocking out the traffic matched by the rule. All switch models require at least some time to enforce the rules after they have been provided by the firewall. Some models can activate the rules within a second while others require up to a minute or even beyond. Another limitation is the maximum number of rules supported by the switch. Some switches support only 50 rules while others support up to 800 (usually, in order to block a host or network, one rule per switch port is needed). When this limit has been reached no more hosts or networks will be blocked out. Zone Defense uses the ACL rule set on the switch and will initially purge all entries on the switch. All pre-configured ACLs will be lost. 28.6 Scenario: Setting Up Zone Defense The following simple example illustrates the steps needed to set up Zone Defense function in D-Link firewalls. We assume that all the interfaces on the firewall have already been properly configured. Example: Configuring Zone Defense In this simplified scenario, a HTTP threshold of 10 connections/second is applied. If the connections exceed this limitation, the firewall will block the specific host (in network range 192.168.2.0/24 for example) from accessing the switch completely. A D-Link switch model DES-3226S is used in this case, with a management interface address 192.168.1.250 connecting to the firewall's interface address 192.168.1.1. This firewall interface is added into the exclude list to prevent D-Link Firewalls User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365

296
Chapter 28. Zone Defense
adding the firewall’s interface IP or MAC address connecting towards the
Zone Defense switch to the Exclude list. This prevents the firewall from
being accidentally blocked out.
28.5
Limitations
Depending on the switch model, various limitations are in effect. The first
one is the latency between the triggering of a block rule to the moment of
the switch(es) actually blocking out the traffic matched by the rule. All
switch models require at least some time to enforce the rules after they
have been provided by the firewall. Some models can activate the rules
within a second while others require up to a minute or even beyond.
Another limitation is the maximum number of rules supported by the
switch. Some switches support only 50 rules while others support up to 800
(usually, in order to block a host or network,
one rule per switch port
is
needed). When this limit has been reached no more hosts or networks will
be blocked out.
Zone Defense uses the ACL rule set on the switch and will initially purge
all entries on the switch. All pre-configured ACLs will be
lost
.
28.6
Scenario
: Setting Up Zone Defense
The following simple example illustrates the steps needed to set up Zone
Defense function in D-Link firewalls. We assume that all the interfaces on
the firewall have already been properly configured.
Example
:
Configuring Zone Defense
In this simplified scenario, a HTTP threshold of 10 connections/second is
applied. If the connections exceed this limitation, the firewall will block the
specific host (in network range 192.168.2.0/24 for example) from accessing
the switch completely.
A D-Link switch model DES-3226S is used in this case, with a management
interface address 192.168.1.250 connecting to the firewall’s interface address
192.168.1.1. This firewall interface is added into the exclude list to prevent
D-Link Firewalls User’s Guide