How Can I Protect Against Ip Spoofing Attacks - ZyXEL Communications P-660H-TX Support Notes

Adsl2+ 4-port gateway
Table of Contents

Advertisement

16. How can I protect against IP spoofing attacks?

The P-660H-Tx v2's filter sets provide a means to protect against IP spoofing
attacks. The basic scheme is as follows:
For the input data filter:
• Deny packets from the outside that claim to be from the inside
• Allow everything that is not spoofing us
Filter rule setup:
• Filter type =TCP/IP Filter Rule
• Active =Yes
• Source IP Addr =a.b.c.d
• Source IP Mask =w.x.y.z
• Action Matched =Drop
• Action Not Matched =Forward
Where a.b.c.d is an IP address on your local network and w.x.y.z is your
netmask:
For the output data filters:
• Deny bounce back packet
• Allow packets that originate from us
Filter rule setup:
• Filter Type =TCP/IP Filter Rule
• Active =Yes
• Destination IP Addr =a.b.c.d
• Destination IP Mask =w.x.y.z
• Action Matched =Drop
• Action No Matched =Forward
Where a.b.c.d is an IP address on your local network and w.x.y.z is your
netmask.
All contents copyright © 2006 ZyXEL Communications Corporation.
P-660H-Tx v2 Support Notes
9

Advertisement

Table of Contents
loading

This manual is also suitable for:

P-660h-tx v2 series

Table of Contents