II-2 Security
II-2-1 Firewall Filters
A network firewall monitors traffic travelling between networks, with the ability to selectively allow
or block traffic using a predefined set of security rules. This helps to maintain the integrity of
networks by stopping unauthorized access and the exchange of sensitive information.
LAN users are provided with secured protection by the following firewall facilities:
User-configurable IP filter (Data Filter).
Stateful Packet Inspection (SPI): tracks packets and denies unsolicited incoming data
Selectable Denial of Service (DoS) /Distributed DoS (DDoS) attacks protection
Data Filter
All traffic, both incoming and outgoing, that does not trigger a PPP connection attempt (either
because a PPP connection is not necessary, or the required PPP connection has already been
established) is checked against the Data Filter, and will be allowed or blocked according to the rules
configured within.
Stateful Packet Inspection (SPI)
Stateful inspection is a firewall architecture that works at the network layer. Unlike legacy static
packet filtering, which examines a packet based on the information in its header, stateful inspection
builds up a state machine to track each connection traversing all interfaces of the firewall and
makes sure they are valid. The stateful firewall of Vigor router not only examines the header
information also monitors the state of the connection.
Denial of Service (DoS) Defense
DoS attacks are categorized into two types: flooding-type attacks and vulnerability attacks.
Flooding-type attacks attempts to exhaust system resources while vulnerability attacks attempts to
paralyze the system by exploiting vulnerabilities of protocols or operation systems.
Vigor's DoS Defense functionality detects DoS attacks and mitigates their damage by inspecting
every incoming packet, and malicious packets will be blocked. If Syslog is enabled, alert messages
will also be sent. Abnormal traffic flow such as flood and port scan attacks that exceed allowable
thresholds are also blocked.
159
Need help?
Do you have a question about the Vigor2136 Series and is the answer not in the manual?
Questions and answers