ProSafe Quad WAN Gigabit Firewall FR538G Reference Manual
4-20
Firewall Protection and Content Filtering
v1.0, November 2007
–
Block UDP Flood.
A UDP flood is a form of denial of service attack that can be initiated
when one machine sends a large number of UDP packets to random ports on a remote
host. As a result, the distant host will (1) check for the application listening at that port, (2)
see that no application is listening at that port and (3) reply with an ICMP Destination
Unreachable packet.
When the victimized system is flooded, it is forced to send many ICMP packets,
eventually making it unreachable by other clients. The attacker may also spoof the IP
address of the UDP packets, ensuring that the excessive ICMP return packets do not reach
him, thus making the attacker’s network location anonymous.
–
Block Non-standard Packets.
Abnormal packets are often used by hackers, especially for
DoS attacks, but may also be generated by other network devices. This setting should
normally be enabled.
To enable the appropriate DoS and DDoS Checks for your environment:
1.
Select
Security
> Firewall from the main menu and then the select the
DoS & DDoS
tab. The
DoS & DDoS
screen will display.
2.
Select the desired checkboxes in the
DoS Protection
and
Defense Agent DDoS Attack
you
wish to initiate.
3.
Click
Apply
to save your settings; otherwise, click
Reset
to return to the previous settings.
Imposing Session Limits
This screen allows you to specify whether or not to impose a session limit for a network client.
Setting session limits can be useful for managing P2P software, such as BT (bit torrent), emule,
Figure 4-14
Summary of Contents for ProSafe Quad WAN FR538G
Page 12: ...xii Contents v1 0 November 2007...
Page 16: ...ProSafe Quad WAN Gigabit Firewall FR538G Reference Manual xvi v1 0 November 2007...
Page 26: ...ProSafe Quad WAN Gigabit Firewall FR538G Reference Manual 1 10 Introduction v1 0 November 2007...
Page 27: ...ProSafe Quad WAN Gigabit Firewall FR538G Reference Manual Introduction 1 11 v1 0 November 2007...
Page 28: ...ProSafe Quad WAN Gigabit Firewall FR538G Reference Manual 1 12 Introduction v1 0 November 2007...