ZyXEL Communications ZYWALL 2 PLUS User Manual page 649

Internet security appliance
Hide thumbs Also See for ZYWALL 2 PLUS:
Table of Contents

Advertisement

Table 239 Firewall Commands (continued)
FUNCTION
Sets
ZyWALL 2 Plus User's Guide
COMMAND
config edit firewall attack
minute-high <0-255>
config edit firewall attack
minute-low <0-255>
config edit firewall attack
max-incomplete-high <0-255>
config edit firewall attack
max-incomplete-low <0-255>
config edit firewall attack
tcp-max-incomplete <0-255>
config edit firewall set <set
#> name <desired name>
Config edit firewall set <set
#> default-permit <forward |
block>
Config edit firewall set <set
#> icmp-timeout <seconds>
Config edit firewall set <set
#> udp-idle-timeout <seconds>
Config edit firewall set <set
#> connection-timeout
<seconds>
Config edit firewall set <set
#> fin-wait-timeout <seconds>
Appendix H Firewall Commands
DESCRIPTION
This command sets the threshold rate of new
half-open sessions per minute where the
ZyWALL starts deleting old half-opened
sessions until it gets them down to the
minute-low threshold.
This command sets the threshold of half-open
sessions where the ZyWALL stops deleting
half-opened sessions.
This command sets the threshold of half-open
sessions where the ZyWALL starts deleting
old half-opened sessions until it gets them
down to the max incomplete low.
This command sets the threshold where the
ZyWALL stops deleting half-opened sessions.
This command sets the threshold of half-open
TCP sessions with the same destination
where the ZyWALL starts dropping half-open
sessions to that destination.
This command sets a name to identify a
specified set.
This command sets whether a packet is
dropped or allowed through, when it does not
meet a rule within the set.
This command sets the time period to allow
an ICMP session to wait for the ICMP
response.
This command sets how long a UDP
connection is allowed to remain inactive
before the ZyWALL considers the connection
closed.
This command sets how long ZyWALL waits
for a TCP session to be established before
dropping the session.
This command sets how long the ZyWALL
leaves a TCP session open after the firewall
detects a FIN-exchange (indicating the end of
the TCP session).
649

Advertisement

Table of Contents
loading

Table of Contents