Attack Alert; Threshold Values; Figure 9-4 E-Mail Log - ZyXEL Communications ZyXEL ZyWALL 50 User Manual

Internet security gateway
Hide thumbs Also See for ZyXEL ZyWALL 50:
Table of Contents

Advertisement

Subject:
Firewall Alert From ZyWALL
Date:
Fri, 07 Apr 2000 10:05:42
From:
user@zyxel.com
To:
user@zyxel.com
1|Apr
7 00 |From:192.168.1.1
|forward
| 09:54:03 |UDP
src port:00520 dest port:00520
2|Apr
7 00 |From:192.168.1.131
|forward
| 09:54:17 |UDP
src port:00520 dest port:00520
3|Apr
7 00 |From:192.168.1.6
| 09:54:19 |UDP
src port:03516 dest port:00053
...................................{snip}.........................................
...................................{snip}.........................................
126|Apr
7 00 |From:192.168.1.1
|forward
| 10:05:00 |UDP
src port:00520 dest port:00520
127|Apr
7 00 |From:192.168.1.131
|forward
| 10:05:17 |UDP
src port:00520 dest port:00520
128|Apr
7 00 |From:192.168.1.1
|forward
| 10:05:30 |UDP
src port:00520 dest port:00520
End of Firewall Log
9.4

Attack Alert

Attack alerts are the first defense against DOS attacks. In the Attack Alert screen, shown later, you may
choose to generate an alert whenever an attack is detected. For DoS attacks, the ZyWALL uses thresholds to
determine when to drop sessions that do not become fully established. These thresholds apply globally to all
sessions.
You can use the default threshold values, or you can change them to values more suitable to your security
requirements.

9.4.1 Threshold Values

Tune these parameters when something is not working and after you have checked the firewall counters.
These default values should work fine for normal small offices with ADSL bandwidth. Factors influencing
choices for threshold values are:
1.
The maximum number of opened sessions.
Using the ZyWALL Web Configurator
The date format here
is Day-Month-Year.
To:192.168.1.255
|default policy
|<1,00>
To:192.168.1.255
|default policy
|<1,00>
To:10.10.10.10 |match
|<1,01>
To:192.168.1.255
|match
|<1,02>
To:192.168.1.255
|match
|<1,02>
To:192.168.1.255
|match
|<1,02>

Figure 9-4 E-mail Log

ZyWALL 50 Internet Security Gateway
You may edit the
subject title
The date format here
is Month-Day-Year.
|
The time format is
Hour-Minute-Second.
|
|forward
|
|
"End of Log" message
shows that a complete
|
log has been sent.
|
9-7

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zw50

Table of Contents