ZyXEL Communications ZyXEL ZyWALL 2WE User Manual page 168

Zyxel internet security gateway user's guide
Hide thumbs Also See for ZyXEL ZyWALL 2WE:
Table of Contents

Advertisement

ZyWALL 2 and ZyWALL 2WE
FIELD
One Minute High
Maximum Incomplete
Low
Maximum Incomplete
High
TCP Maximum
Incomplete
15-6
Table 15-1 Attack Alert
DESCRIPTION
This is the rate of new half-open sessions
that causes the firewall to start deleting
half-open sessions. When the rate of new
connection attempts rises above this
number, the ZyWALL deletes half-open
sessions as required to accommodate
new connection attempts.
This is the number of existing half-open
sessions that causes the firewall to stop
deleting half-open sessions. The ZyWALL
continues to delete half-open requests as
necessary, until the number of existing
half-open sessions drops below this
number.
This is the number of existing half-open
sessions that causes the firewall to start
deleting half-open sessions. When the
number of existing half-open sessions
rises above this number, the ZyWALL
deletes half-open sessions as required to
accommodate new connection requests.
Do not set Maximum Incomplete High to
lower than the current Maximum
Incomplete Low number.
This is the number of existing half-open
TCP sessions with the same destination
host IP address that causes the firewall to
start dropping half-open sessions to that
same destination host IP address. Enter a
number between 1 and 250. As a general
rule, you should choose a smaller number
for a smaller network, a slower system or
limited bandwidth.
DEFAULT VALUES
100 half-open sessions per
minute. The above numbers
cause the ZyWALL to start
deleting half-open sessions
when more than 100 session
establishment attempts have
been detected in the last minute,
and to stop deleting half-open
sessions when fewer than 80
session establishment attempts
have been detected in the last
minute.
80 existing half-open sessions.
100 existing half-open sessions.
The above values causes the
ZyWALL to start deleting half-
open sessions when the number
of existing half-open sessions
rises above 100, and to stop
deleting half-open sessions with
the number of existing half-open
sessions drops below 80.
10 existing half-open TCP
sessions.
Firewall Configuration

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zywall 2

Table of Contents