NETGEAR ProSafe SRX5308 Reference Manual page 110

Gigabit quad wan ssl vpn firewall
Hide thumbs Also See for ProSafe SRX5308:
Table of Contents

Advertisement

ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
3.
Enter the settings as explained in the following table:
Table 21. Session Limit screen settings
Setting
Session Limit
Session Limit Control
User Limit Parameter
User Limit
Total Number of
Packets Dropped due
to Session Limit
Session Timeout
TCP Timeout
UDP Timeout
ICMP Timeout
4.
Click Apply to save your settings.
Description
From the drop-down list, select one of the following options:
• When single IP exceeds. When the limit is reached, no new session is allowed
from the IP address. A new session is allowed only when an existing session is
terminated or times out.
• Single IP Cannot Exceed. When the limit is reached, no new session is allowed
from the IP address for a specified period or all sessions from the IP address
are terminated and new sessions are blocked for a specified period. You need to
specify the action and period by selecting one of the following radio buttons:
- Block IP to add new session for. No new session is allowed from the IP
address for a period. In the time field, specify the period in seconds.
- Block IP's all connections for. All sessions from the IP address are
terminated and new sessions are blocked for a period. In the time field,
specify the period in seconds.
From the User Limit Parameter drop-down list, select one of the following options:
• Percentage of Max Sessions. A percentage of the total session connection
capacity of the VPN firewall.
• Number of Sessions. An absolute number of maximum sessions.
Enter a number to indicate the user limit. The default value is 3.
If the User Limit Parameter is set to Percentage of Max Sessions, the number
specifies the maximum number of sessions that are allowed from a single-source
device as a percentage of the total session connection capacity of the VPN
firewall. (The session limit is per-device based.)
If the User Limit Parameter is set to Number of Sessions, the number specifies an
absolute value.
Note:
Some protocols such as FTP and RSTP create two sessions per
connection, which should be considered when configuring a session limit.
This is a nonconfigurable counter that displays the total number of dropped
packets when the session limit is reached.
For each protocol, specify a time-out in seconds. A session expires if no data for
the session is received for the duration of the time-out period. The default time-out
periods are 1200 seconds for TCP sessions, 180 seconds for UDP sessions, and
8 seconds for ICMP sessions.
Firewall Protection
110

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents