User Manual

118
destination port.
DMAC = SMAC
Drops the packets if the destination MAC address is equal to the
source MAC address.
Null Scan
Attach
Drops the packets with NULL scan.
X-Mas
Scan Attack
Drops the packets if the sequence number is zero, and the FIN,
URG and PSH bits are set.
TCP SYN-FIN
Attack
Drops the packets with SYN and FIN bits set.
TCP SYN-RST
Attack
Drops the packets with SYN and RST bits set
ICMP Fragment
Drops the fragmented ICMP packets.
TCP SYN
(SPORT<1024)
Drops SYN packets with sport less than 1024.
TCP Fragment
(Offset = 1)
Drops the TCP fragment packets with offset equals to one.
Ping Max Size
Specify the maximum size of the ICMPv4/ICMPv6 ping packets.
The valid range is from 0 to 65535 bytes, and the default value is
512 bytes.
IPv6 Min
Fragment
Checks the minimum size of IPv6 fragments, and drops the
packets smaller than the minimum size. The valid range is from 0
to 65535 bytes, and default value is 1240 bytes.
Smurf Attack
Avoids smurf attack. The length range of the netmask is from 0 to
323 bytes, and default length is 0 bytes.
III-10-7-2. Port Setting
To configure and display the state of DoS protection for interfaces, click Security > DoS >
Port Setting.