ZyXEL P-202H User Guide - Page 93
Table 22
View all ZyXEL P-202H manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 93 highlights
Figure 33 Firewall > Alert P-202H Plus v2 User's Guide The following table describes the labels in this screen. Table 22 Firewall > Alert LABEL Generate alert when attack detected Denial of Service Thresholds One Minute Low One Minute High Maximum Incomplete Low Maximum Incomplete High TCP Maximum Incomplete DESCRIPTION Select this check box to generate an alert whenever an attack is detected. This is the rate of new half-open sessions that causes the firewall to stop deleting half-open sessions. The ZyXEL Device continues to delete half-open sessions as necessary, until the rate of new connection attempts drops below this number. This is the rate of new half-open sessions that causes the firewall to start deleting half-open sessions. When the rate of new connection attempts rises above this number, the ZyXEL Device deletes half-open sessions as required to accommodate new connection attempts. This is the number of existing half-open sessions that causes the firewall to stop deleting half-open sessions. The ZyXEL Device continues to delete half-open requests as necessary, until the number of existing half-open sessions drops below this number. This is the number of existing half-open sessions that causes the firewall to start deleting half-open sessions. When the number of existing half-open sessions rises above this number, the ZyXEL Device deletes half-open sessions as required to accommodate new connection requests. Do not set Maximum Incomplete High to lower than the current Maximum Incomplete Low number. This is the number of existing half-open TCP sessions with the same destination host IP address that causes the firewall to start dropping half-open sessions to that same destination host IP address. Enter a number between 1 and 256. As a general rule, you should choose a smaller number for a smaller network, a slower system or limited bandwidth. Chapter 9 Firewall Configuration 92