158
eircom D1000 modem U
ser’s Guide
Chapter 13 Firewall
The following table describes the labels in this screen.
Table 62
Security > Firewall > DoS > Advanced
LABEL
DESCRIPTION
TCP SYN-Request
Count
This is the rate of new TCP half-open sessions per second that causes the firewall to
start deleting half-open sessions. When the rate of new connection attempts rises
above this number, the Device deletes half-open sessions as required to
accommodate new connection attempts.
UDP Packet Count
This is the rate of new UDP half-open sessions per second that causes the firewall to
start deleting half-open sessions. When the rate of new connection attempts rises
above this number, the Device deletes half-open sessions as required to
accommodate new connection attempts.
ICMP Echo-Request
Count
This is the rate of new ICMP Echo-Request half-open sessions per second that causes
the firewall to start deleting half-open sessions. When the rate of new connection
attempts rises above this number, the Device deletes half-open sessions as required
to accommodate new connection attempts.
ICMP Redirect
Select
Enable
to monitor for and block ICMP redirect attacks.
An ICMP redirect attack is one where forged ICMP redirect messages can force the
client device to route packets for certain connections through an attacker’s host.
DoS Log(Log Level:
DEBUG)
Select
Enable
to log DoS attacks. See
Chapter 16 on page 173
for information on
viewing logs.
Back
Click this button to return to the previous screen.
Apply
Click this to save your changes.
Cancel
Click this to restore your previously saved settings.
13.6 Firewall Technical Reference
This section provides some technical background information about the topics covered in this
chapter.
13.6.1 Firewall Rules Overview
Your customized rules take precedence and override the Device’s default settings. The Device
checks the source IP address, destination IP address and IP protocol type of network traffic against
the firewall rules (in the order you list them). When the traffic matches a rule, the Device takes the
action specified in the rule.
Firewall rules are grouped based on the direction of travel of packets to which they apply:
• LAN to Router
• WAN to LAN
• LAN to WAN
• WAN to Router
Note: The LAN includes both the LAN port and the WLAN.
By default, the Device’s stateful packet inspection allows packets traveling in the following
directions:
• LAN to Router
These rules specify which computers on the LAN can manage the Device (remote management).
Summary of Contents for eircom D1000
Page 2: ...Copyright 2013 ZyXEL Communications Corporation...
Page 3: ......
Page 12: ...10 eircom D1000 modem User s Guide...
Page 13: ...PART I User s Guide 11...
Page 14: ...12...
Page 18: ...16 eircom D1000 modem User s Guide...
Page 26: ...Chapter 2 Introducing the Web Configurator 24 eircom D1000 modem User s Guide...
Page 27: ...PART II Technical Reference 25...
Page 28: ...26...
Page 78: ...76 eircom D1000 modem User s Guide Chapter 5 Wireless LAN...
Page 110: ...10 8 eircom D1000 modem User s Guide Chapter 6 Home Networking...
Page 126: ...Chapter 8 Quality of Service QoS 124 eircom D1000 modem User s Guide...
Page 136: ...134 eircom D1000 modem User s Guide Chapter 9 Network Address Translation NAT...
Page 148: ...146 eircom D1000 modem User s Guide Chapter 12 Filter...
Page 168: ...Chapter 14 Parental Control 166 eircom D1000 modem User s Guide...
Page 174: ...Chapter 15 Certificates 172 eircom D1000 modem User s Guide...
Page 180: ...178 eircom D1000 modem User s Guide Chapter 17 Traffic Status...
Page 182: ...180 eircom D1000 modem User s Guide Chapter 18 User Account...
Page 184: ...182 eircom D1000 modem User s Guide Chapter 19 System Setting...
Page 187: ...185 eircom D1000 modem User s Guide Chapter 20 Time Setting...
Page 188: ...Chapter 20 Time Setting 186 eircom D1000 modem User s Guide...
Page 196: ...Chapter 23 Backup Restore 194 eircom D1000 modem User s Guide...
Page 210: ...Chapter 25 Diagnostic 208 eircom D1000 modem User s Guide...
Page 216: ...214 eircom D1000 modem User s Guide Chapter 27 LED Descriptions...