D-Link DFL-2500 User Guide - Page 315
Limitations, Setting Up Zone Defense
![]() |
View all D-Link DFL-2500 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 315 highlights
296 Chapter 28. Zone Defense adding the firewall's interface IP or MAC address connecting towards the Zone Defense switch to the Exclude list. This prevents the firewall from being accidentally blocked out. 28.5 Limitations Depending on the switch model, various limitations are in effect. The first one is the latency between the triggering of a block rule to the moment of the switch(es) actually blocking out the traffic matched by the rule. All switch models require at least some time to enforce the rules after they have been provided by the firewall. Some models can activate the rules within a second while others require up to a minute or even beyond. Another limitation is the maximum number of rules supported by the switch. Some switches support only 50 rules while others support up to 800 (usually, in order to block a host or network, one rule per switch port is needed). When this limit has been reached no more hosts or networks will be blocked out. Zone Defense uses the ACL rule set on the switch and will initially purge all entries on the switch. All pre-configured ACLs will be lost. 28.6 Scenario: Setting Up Zone Defense The following simple example illustrates the steps needed to set up Zone Defense function in D-Link firewalls. We assume that all the interfaces on the firewall have already been properly configured. Example: Configuring Zone Defense In this simplified scenario, a HTTP threshold of 10 connections/second is applied. If the connections exceed this limitation, the firewall will block the specific host (in network range 192.168.2.0/24 for example) from accessing the switch completely. A D-Link switch model DES-3226S is used in this case, with a management interface address 192.168.1.250 connecting to the firewall's interface address 192.168.1.1. This firewall interface is added into the exclude list to prevent D-Link Firewalls User's Guide
![](/manual_guide/products/dlink-dfl2500-user-guide-83bdca9/315.png)