AMG1001-T/AMG1011-T Series User’s Guide
82
C
H A P T E R
1 3
Firewall
13.1 Overview
This chapter shows you how to enable the AMG1001-T/AMG1011-T firewall. Use the firewall to
protect your AMG1001-T/AMG1011-T and network from attacks by hackers on the Internet and
control access to it. By default the firewall:
• allows traffic that originates from your LAN computers to go to all other networks.
• blocks traffic that originates on other networks from going to the LAN.
• blocks SYN and port scanner attacks.
By default, the AMG1001-T/AMG1011-T blocks DDOS, LAND and Ping of Death attacks whether the
firewall is enabled or disabled.
13.1.1 What You Can Do in the Firewall Screens
Use the
Firewall
screen (
Section 13.2 on page 83
) to enable firewall and/or SPI on the AMG1001-
T/AMG1011-T.
13.1.2 What You Need to Know About Firewall
SYN Attack
A SYN attack floods a targeted system with a series of SYN packets. Each packet causes the
targeted system to issue a SYN-ACK response. While the targeted system waits for the ACK that
follows the SYN-ACK, it queues up all outstanding SYN-ACK responses on a backlog queue. SYN-
ACKs are moved off the queue only when an ACK comes back or when an internal timer terminates
the three-way handshake. Once the queue is full, the system will ignore all incoming SYN requests,
making the system unavailable for legitimate users.
DoS
Denials of Service (DoS) attacks are aimed at devices and networks with a connection to the
Internet. Their goal is not to steal information, but to disable a device or network so users no longer
have access to network resources. The ZyXEL Device is pre-configured to automatically detect and
thwart all known DoS attacks.
DDoS
A DDoS attack is one in which multiple compromised systems attack a single target, thereby
causing denial of service for users of the targeted system.
Summary of Contents for AMG1001-T Series
Page 10: ...10 PART I User s Guide ...
Page 11: ...11 ...
Page 20: ...Chapter 1 Introducing the AMG1001 T AMG1011 T AMG1001 T AMG1011 T Series User s Guide 20 ...
Page 25: ...25 PART II Technical Reference ...
Page 26: ...26 ...