Operation Manual

Protect Your Network
6-19
Enable Block ICMP
fragment
Click the checkbox to activate the Block ICMP fragment
function. Any ICMP packets with more fragment bit set
are dropped.
Enable Block
Unknown Protocol
Click the checkbox to activate the Block Unknown
Protocol function. Individual IP packet has a protocol
field in the datagram header to indicate the protocol
type running over the upper layer. However, the
protocol types greater than 100 are reserved and
undefined at this time. Therefore, the router should
have ability to detect and reject this kind of packets.
6-A.3 Warning Message
All the warning messages will be sent to syslog client after you enable the
syslog function. The administrator can setup the syslog client in the
Syslog Setup by using Web Configurator. Thus, the administrator can
look at the warning messages from DoS Defense functionality through the
DrayTek Sylsog daemon. The format for this kind of the warning messages
is similar to those in IP Filter/Firewall except for the preamble keyword
“DoS”, followed by a name to indicate what kind of attacks is detected.