Firewall; Dos Defense - Draytek Vigor2130 Series User Manual

High speed gigabit router
Hide thumbs Also See for Vigor2130 Series:
Table of Contents

Advertisement

4
.
4
F
i
r
e
w
a
l
l
4
.
4
F
i
r
e
w
a
l
l
B
a
s
i
c
s
B
a
s
i
c
s
While the broadband users demand more bandwidth for multimedia, interactive applications,
or distance learning, security has been always the most concerned. The firewall of the Vigor
router helps to protect your local network against attack from unauthorized outsiders. It also
restricts users in the local network from accessing the Internet. Furthermore, it can filter out
specific packets that trigger the router to build an unwanted outgoing connection.
D
e
n
i
a
l
D
e
n
i
a
l
The DoS Defense functionality helps you to detect and mitigate the DoS attack. The attacks
are usually categorized into two types, the flooding-type attacks and the vulnerability attacks.
The flooding-type attacks will attempt to exhaust all your system's resource while the
vulnerability attacks will try to paralyze the system by offending the vulnerabilities of the
protocol or operation system.
The DoS Defense function enables the Vigor router to inspect every incoming packet based on
the attack signature database. Any malicious packet that might duplicate itself to paralyze the
host in the secure LAN will be strictly blocked and a Syslog message will be sent as warning, if
you set up Syslog server.
Also the Vigor router monitors the traffic. Any abnormal traffic flow violating the pre-defined
parameter, such as the number of thresholds, is identified as an attack and the Vigor router will
activate its defense mechanism to mitigate in a real-time manner.
Below shows the menu items for Firewall.
4
.
4
.
1
D
o
S
D
e
4
.
4
.
1
D
o
S
D
e
Click Firewall and click DoS Defense to open the setup page. Storm control for the switch is
configured on this page.
Frame Type
Status
Rate
Vigor2130 Series User's Guide
f
o
r
F
i
r
e
w
a
l
l
f
o
r
F
i
r
e
w
a
l
l
o
f
S
e
r
v
i
c
e
(
D
o
S
)
o
f
S
e
r
v
i
c
e
(
D
o
S
)
f
e
n
s
e
f
e
n
s
e
D
e
f
e
n
s
e
D
e
f
e
n
s
e
Set the Unicast storm rate control, multicast storm rate control,
and a broadcast storm rate control for your router.
Check this box to enable storm control status for the frame type.
The unit is packet per second (pps). Use the drop down list to
set the rate for data transmission. The rate is 2^n, where n is
equal to or less than 15, or "No Limit". The unit of the rate can
be either pps (packets per second) or kpps (kilopackets per
129

Advertisement

Table of Contents
loading

Table of Contents