D-Link DSL-504T Product Manual - Page 67

Advanced-Firewall continued

Page 67 highlights

DSL-504T User's Manual Advanced - Firewall Advanced-Firewall (continued) When DoS, Port Scan, or Service Filtering Protection is enabled, it will create a firewall policy to protect your network against the following: Dos Protection SYN Flood check ICMP Redirection check Port Scan Protection Nmap/FIN attack URG/PSH attack Xmas Tree Scan Null Scan attack SYN/RST attack Service Filtering Ping from WAN Telnet from WAN FTP from WAN DNS from WAN IKE from WAN RIP from WAN DHCP from WAN A DoS "denial-of-service" attack is characterized by an explicit attempt by attackers to prevent legitimate users of a service from using that service. Examples include: attempts to "flood" a network, thereby preventing legitimate network traffic, attempts to disrupt connections between two machines, thereby preventing access to a service, attempts to prevent a particular individual from accessing a service, or, attempts to disrupt service to a specific system or person. Port scan protection is designed to block attempts to discover vulnerable ports or services that might be exploited in an attack from the WAN. The Service Filtering options allow you to block FTP, Telnet response, Pings, etc, from the external network. Check the category you want to block to enable filtering of that type of packet. When you have selected the desired Firewall policies, click the Apply button to enforce the policies. Remember to save any configuration changes. D-Link Systems, Inc. 67

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99

67
DSL-504T User’s Manual
D-Link Systems, Inc.
Advanced - Firewall
Advanced-Firewall (continued)
When DoS, Port Scan, or Service Filtering Protection is enabled, it will create a firewall
policy to protect your network against the following:
Dos Protection
SYN Flood check
ICMP Redirection
check
Port
S c a n
Protection
Nmap/FIN attack
URG/PSH attack
Xmas Tree Scan
Null Scan attack
SYN/RST attack
Service Filtering
Ping from WAN
Telnet from WAN
FTP from WAN
DNS from WAN
IKE from WAN
RIP from WAN
DHCP from WAN
A DoS “denial-of-service” attack is characterized by an explicit attempt by attackers to
prevent legitimate users of a service from using that service. Examples include: attempts
to “flood” a network, thereby preventing legitimate network traffic, attempts to disrupt
connections between two machines, thereby preventing access to a service, attempts to
prevent a particular individual from accessing a service, or, attempts to disrupt service
to a specific system or person.
Port scan protection is designed to block attempts to discover vulnerable ports or
services that might be exploited in an attack from the WAN.
The Service Filtering options allow you to block FTP, Telnet response, Pings, etc, from
the external network.
Check the category you want to block to enable filtering of that
type of packet.
When you have selected the desired Firewall policies, click the
Apply
button to enforce
the policies. Remember to save any configuration changes.