Attack Alert; Figure 11-3 E-Mail Log - ZyXEL Communications Prestige 652 User Manual

Zyxel adsl security router user's guide
Hide thumbs Also See for Prestige 652:
Table of Contents

Advertisement

Prestige 652 ADSL Security Router
Subject:
Firewall Alert From Prestige
Date:
Fri, 07 Apr 2000 10:05:42
From:
user@zyxel.com
To:
user@zyxel.com
1|Apr
7 00 |From:192.168.1.1
|forward
| 09:54:03 |UDP
2|Apr
7 00 |From:192.168.1.131
|forward
| 09:54:17 |UDP
3|Apr
7 00 |From:192.168.1.6
| 09:54:19 |UDP
...................................{snip}.........................................
...................................{snip}.........................................
126|Apr
7 00 |From:192.168.1.1
|forward
| 10:05:00 |UDP
127|Apr
7 00 |From:192.168.1.131
|forward
| 10:05:17 |UDP
128|Apr
7 00 |From:192.168.1.1
|forward
| 10:05:30 |UDP
End of Firewall Log

11.4 Attack Alert

Attack alerts are the first defense against DoS attacks. In the Attack Alert screen, shown later, you may
choose to generate an alert whenever an attack is detected. For DoS attacks, the Prestige uses thresholds to
determine when to drop sessions that do not become fully established. These thresholds apply globally to all
sessions.
You can use the default threshold values, or you can change them to values more suitable to your security
requirements.
11.4.1 Threshold Values
Tune these parameters when something is not working and after you have checked the firewall counters.
These default values should work fine for normal small offices with ADSL bandwidth. Factors influencing
choices for threshold values are:
1. The maximum number of opened sessions.
11-6
To:192.168.1.255
src port:00520 dest port:00520
To:192.168.1.255
src port:00520 dest port:00520
To:10.10.10.10 |match
src port:03516 dest port:00053
To:192.168.1.255
src port:00520 dest port:00520
To:192.168.1.255
src port:00520 dest port:00520
To:192.168.1.255
src port:00520 dest port:00520

Figure 11-3 E-mail Log

The date format here
is Day-Month-Year.
|default policy
|<1,00>
|default policy
|<1,00>
|forward
|<1,01>
|match
|<1,02>
|match
|<1,02>
|match
|<1,02>
Using the Prestige Web Configurator
You may edit the
subject title
The date format here
is Month-Day-Year.
|
The time format is
Hour-Minute-Second.
|
|
|
"End of Log" message
shows that a complete
|
log has been sent.
|

Advertisement

Table of Contents
loading

Table of Contents