User manual

Reference: Configuration options
Avira Professional Security - User Manual (Status: 14 Dec. 2012) 148
Setting
Rules
Low
Assume a UDP port scan if 50 or more ports were
scanned in 5,000 milliseconds.
When detected, log attacker's IP and don't add
rule to block the attack.
Medium
Assume a UDP port scan if 50 or more ports were
scanned in 5,000 milliseconds.
When detected, log attacker's IP and add rule to
block the attack.
High
Same rule as for medium level.
Ports
With a mouse click on the link a dialog box appears in which you can enter the number
of ports that must have been scanned so that a UDP port scan is assumed.
Port scan time window
With a mouse click on this link a dialog box appears in which you can enter the time
span for a certain number of port scans, so that a UDP port scan is assumed.
Report file
With a mouse click on the link you have the choice to log or not to log the attacker's IP
address.
Rule
With a mouse click on the link you have the choice to add or not to add the rule to
block the UDP port scan attack.
Incoming Rules
Incoming rules are defined to control incoming data traffic by the Avira FireWall.
Warning
When a packet is filtered the corresponding rules are applied successively,
therefore the rule order is very important. Change the rule order only if you are
completely aware of what you are doing.
Predefined rules for the TCP traffic monitor