Netgear FVS338 FVS338 Reference Manual - Page 69

Inbound Rules Examples, Total Number of Packets Dropped due to Session Limit

Page 69 highlights

FVS338 ProSafe VPN Firewall 50 Reference Manual To enable Session Limit: 1. Click the Yes radio button under Do you want to enable Session Limit? 2. From the User Limit Parameter drop-down list, define the maximum number of sessions per IP either as a percentage of maximum sessions or as an absolute value. The percentage is computed on the total connection capacity of the device. 3. Enter the User Limit. If the User Limit Parameter is set to Percentage of Max Sessions, the limit is the maximum number of sessions allowed from a single source machine as a percentage of the total connection capacity. (Session Limit is a machine-based value.) Otherwise, when the User Limit Parameter is set to Number of Sessions, the limit is an absolute value. Note: Some protocols (such as FTP or RSTP) create two sessions per connection which should be considered when configuring Session Limiting. Total Number of Packets Dropped due to Session Limit: Shows total number of packets dropped when session limit is reached. 4. In the Session Timeout section, modify TCP, UDP, and ICMP timeouts as required. A session will time out if it does not receive any data for the duration of the specified timeout. The default values are 1200 seconds for TCP, 180 seconds for UDP, and 8 seconds for ICMP. 5. Click Apply to save your settings. Inbound Rules Examples Hosting A Local Public Web Server If you host a public Web server on your local network, you can define a rule to allow inbound Web (HTTP) requests from any outside IP address to the IP address of your Web server at any time of day. This rule is shown in Figure 4-7: Firewall Protection and Content Filtering v1.0, March 2008 4-13

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198

FVS338 ProSafe VPN Firewall 50 Reference Manual
Firewall Protection and Content Filtering
4-13
v1.0, March 2008
To enable
Session Limit
:
1.
Click the
Yes
radio button under
Do you want to enable Session Limit
?
2.
From the
User Limit Parameter
drop-down list, define the maximum number of sessions per
IP either as a percentage of maximum sessions or as an absolute value.
The percentage is computed on the total connection capacity of the device.
3.
Enter the
User Limit
. If the User Limit Parameter is set to
Percentage of Max Sessions
, the
limit is the maximum number of sessions allowed from a single source machine as a
percentage of the total connection capacity. (Session Limit is a machine-based value.)
Otherwise, when the User Limit Parameter is set to
Number of Sessions
, the limit is an
absolute value.
Total Number of Packets Dropped due to Session Limit
: Shows total number of packets
dropped when session limit is reached.
4.
In the
Session Timeout
section, modify TCP, UDP, and ICMP timeouts as required. A session
will time out if it does not receive any data for the duration of the specified timeout. The
default values are 1200 seconds for TCP, 180 seconds for UDP, and 8 seconds for ICMP.
5.
Click
Apply
to save your settings.
Inbound Rules Examples
Hosting A Local Public Web Server
If you host a public Web server on your local network, you can define a rule to allow inbound Web
(HTTP) requests from any outside IP address to the IP address of your Web server at any time of
day. This rule is shown in
Figure 4-7
:
Note:
Some protocols (such as FTP or RSTP) create two sessions per connection
which should be considered when configuring Session Limiting.