D-Link DIR-825 User Manual page 220

Ac1200 wave 2 mu-mimo wi-fi gigabit router with 3g/lte support and usb port
Hide thumbs Also See for DIR-825:
Table of Contents

Advertisement

DIR-825 AC1200 Wave 2 MU-MIMO Wi-Fi Gigabit Router
with 3G/LTE Support and USB Port
User Manual
In the Per-source IP Flood section, you can enable protection against main types of DoS attacks.
Parameter
TCP/SYN
TCP/FIN
UDP
ICMP
Move the relevant switches to the right. In the threshold field corresponding to the switch, specify
the maximum number of packets which arrive from one IP address within one second. The value of
the field should be greater than zero (for example, 200). Then, in the Other Settings section,
move the Block source IP switch to the right, and in the Block time field, specify the time
period (in seconds) during which the source IP address will be blocked. For example, you can
specify 120. When the threshold value is exceeded, the source of packets will be blocked for the
specified time period.
In the Other Settings section, you can activate additional protection methods.
Parameter
TCP/UDP port scan
IP Land
IP Spoof
IP TearDrop
TCP scan
TCP/SYN with data
Enables protection against a flood with connection requests (TCP
packets with the SYN flag).
Enables protection against a flood with requests for connection
termination (TCP packets with the FIN flag).
Enables protection against a flood with UDP packets.
Enables protection against a flood with ICMP packets.
Blocks the source of TCP or UDP packets which check the ports
state if the router receives more than 200 requests per second from
one IP address. The source of packets will be blocked during the
time period specified in the Block time field (the field is displayed
if the Block source IP switch is moved to the right).
If the switch is moved to the right, the High sensitivity switch is
displayed on the page. Activate the setting to let the router block the
source if it sends more than 10 requests per second.
Blocks TCP packets with the SYN flag in which the source IP
address and port coincides with the destination IP address and port.
Block packets in which the source IP address coincides with the
router's LAN IP address.
Blocks fragmented IP packets if errors can occur upon assembling
these packets.
Blocks TCP packets with invalid flags.
Blocks TCP packets with the SYN flag if they are fragmented or
contain data.
Page 220 of 249
Configuring via Web-based Interface
Description
Description

Advertisement

Table of Contents
loading

Table of Contents