User's Manual

Table Of Contents
Chapter 14 Firewall 163
14.5.2 Configuring Firewall Thresholds
Click Security > Firewall > DoS > Advanced to display the following screen.
Figure 107 Sec
urity > Firewall > DoS > Advanced
The following table describes the labels in this screen.
Table 66 Security >
Firewall > DoS > Advanced
LABEL DESCRIPTION
TCP SYN-Request
Count
This is the rate of new TCP half-open sessions p
er second that causes the firewall to
start deleting half-open sessions. When the rate of new connection attempts rises
above this number, the Device deletes half-open sessions as required to
accommodate new connection attempts.
UDP Packet Count This is the rate of new UDP half-open sessions per second that causes the firewall to
start deleting half-open sessions. When the rate of new connection attempts rises
above this number, the Device deletes half-open sessions as required to
accommodate new connection attempts.
ICMP Echo-Request
Count
This is the rate of new ICMP Echo-Request half-open session
s per second that causes
the firewall to start deleting half-open sessions. When the rate of new connection
attempts rises above this number, the Device deletes half-open sessions as required
to accommodate new connection attempts.
ICMP Redirect Select En
able to monitor for and block ICMP redirect attacks.
An ICMP redirect attack is one where forged ICMP r
edirect messages can force the
client device to route packets for certain connections through an attacker’s host.
DoS Log(Log Level:
DEBUG)
Select Enable to log DoS attacks. See Section 17.2 on page 182 for information on
viewing logs.
OK Click this to save your changes.
Cancel Click this to exit this screen without saving.