Draytek Vigor2955 User Manual page 65

Dual wan ssl vpn appliance
Hide thumbs Also See for Vigor2955:
Table of Contents

Advertisement

S
t
a
t
e
f
u
l
P
a
c
k
e
t
I
n
S
t
a
t
e
f
u
l
P
a
c
k
e
t
I
n
Stateful inspection is a firewall architecture that works at the network layer. Unlike legacy
static packet filtering, which examines a packet based on the information in its header,
stateful inspection builds up a state machine to track each connection traversing all interfaces
of the firewall and makes sure they are valid. The stateful firewall of Vigor router not just
examine the header information also monitor the state of the connection.
D
e
n
i
a
l
o
f
S
e
r
v
i
c
e
D
e
n
i
a
l
o
f
S
e
r
v
i
c
e
The DoS Defense functionality helps you to detect and mitigate the DoS attack. The attacks
are usually categorized into two types, the flooding-type attacks and the vulnerability attacks.
The flooding-type attacks will attempt to exhaust all your system's resource while the
vulnerability attacks will try to paralyze the system by offending the vulnerabilities of the
protocol or operation system.
The DoS Defense function enables the Vigor router to inspect every incoming packet based
on the attack signature database. Any malicious packet that might duplicate itself to paralyze
the host in the secure LAN will be strictly blocked and a Syslog message will be sent as
warning, if you set up Syslog server.
Also the Vigor router monitors the traffic. Any abnormal traffic flow violating the pre-defined
parameter, such as the number of thresholds, is identified as an attack and the Vigor router
will activate its defense mechanism to mitigate in a real-time manner.
The below shows the attack types that DoS/DDoS defense function can detect:
1. SYN flood attack
s
p
e
c
t
i
o
n
(
S
P
I
)
s
p
e
c
t
i
o
n
(
S
P
I
)
(
D
o
S
)
D
e
f
e
n
s
e
(
D
o
S
)
D
e
f
e
n
s
e
9. SYN fragment
55
Vigor2955 User's Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Vigor2950 series

Table of Contents