
Chapter 9 Firewall Configuration
P-661H/HW Series User’s Guide
169
TCP Maximum
Incomplete
An unusually high number of half-open sessions with the same destination host
address could indicate that a DoS attack is being launched against the host.
Specify the number of existing half-open TCP sessions with the same destination
host IP address that causes the firewall to start dropping half-open sessions to
that same destination host IP address. Enter a number between 1 and 256. As a
general rule, you should choose a smaller number for a smaller network, a slower
system or limited bandwidth. The ZyXEL Device sends alerts whenever the TCP
Maximum Incomplete is exceeded.
Action taken
when TCP
Maximum
Incomplete
reached threshold
Select the action that ZyXEL Device should take when the TCP maximum
incomplete threshold is reached.
Delete the
oldest half
open session
when new
connection
request
comes
Select this radio button to clear the oldest half open session when a new
connection request comes.
Deny new
connection
request for
Select this radio button and specify for how long the ZyXEL Device should block
new connection requests when TCP Maximum Incomplete is reached.
Enter the length of blocking time in minutes (between 1 and 256).
Apply Click Apply to save your changes back to the ZyXEL Device.
Cancel Click Cancel to begin configuring this screen afresh.
Table 66 Firewall: Thresholds (continued)
LABEL DESCRIPTION
Kommentare zu diesen Handbüchern