ZyXEL VFG6005 User Guide - Page 47

Security Settings

Page 47 highlights

CHAPTER7 SECURITY SETTINGS 7.1 FIREWALL SETUP 1. Click on [Security] - [Firewall] tab. You will see the following screen. 2. Configure Security Settings following the instructions below. SPI Firewall Protection TCP SYN DoS Protection Select Enable to enable SPI Firewall Protection. Select Disable to disable SPI Firewall Protection. Check to enable TCP SYN DoS Protection. Uncheck to disable TCP SYN DoS Protection. TCP SYN DoS attack sends a flood of TCP/SYN packets. Each of these packets are like a connection request, causing the server to consume computing resources (e.g. memory, CPU) to reply and to continuously wait for the incoming packets. Without TCP SYN Dos Protection, the resources in the server will be easily consumed completely. This will then consequently result in the dysfunction of the server. ICMP Broadcasting Protection The ZyXEL VFG6005 Series VPN Firewall Gateway is able to detect TCP SYN DoS attacks and limits the resource consumption by lowering the incoming request rate by fast recycling the resource. Therefore, the ZyXEL VFG6005 Series VPN Firewall Gateway is still able to serve normal traffic while it is under such an attack. Check to enable ICMP Broadcasting Protection. Uncheck to disable ICMP Broadcasting Protection. ICMP broadcasting attack is a type of DoS attacks. A flood of ICMP broadcasting packets is generated and sent to a server (like the ZyXEL VFG6005 Series VPN 38

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162

38
CHAPTER7 SECURITY SETTINGS
7.1
FIREWALL SETUP
1.
Click on [Security]
[Firewall] tab. You will see the following screen.
2.
Configure Security Settings following the instructions below.
SPI Firewall Protection
Select Enable to enable SPI Firewall Protection.
Select Disable to disable SPI Firewall Protection.
TCP SYN DoS
Protection
Check to enable TCP SYN DoS Protection.
Uncheck to disable TCP SYN DoS Protection.
TCP SYN DoS attack sends a flood of TCP/SYN packets. Each of these packets
are like a connection request, causing the server to consume computing
resources (e.g. memory, CPU) to reply and to continuously wait for the incoming
packets. Without TCP SYN Dos Protection, the resources in the server will be
easily consumed completely. This will then consequently result in the dysfunction
of the server.
The ZyXEL VFG6005 Series VPN Firewall Gateway is able to detect TCP SYN
DoS attacks and limits the resource consumption by lowering the incoming
request rate by fast recycling the resource. Therefore, the ZyXEL VFG6005
Series VPN Firewall Gateway is still able to serve normal traffic while it is under
such an attack.
ICMP Broadcasting
Protection
Check to enable ICMP Broadcasting Protection.
Uncheck to disable ICMP Broadcasting Protection.
ICMP broadcasting attack is a type of DoS attacks. A flood of ICMP broadcasting
packets is generated and sent to a server (like the ZyXEL VFG6005 Series VPN