User's Manual

Table Of Contents
Chapter 12 Firewall 92
12.3.1 The DoS Advanced Screen
Click Security > Firewall > DoS > Advanced to display the following screen.
Figure 65 Fir
ewall > DoS > Advanced
Table 56 Firewall > DoS > Advanced
LABEL DESCRIPTION
TCP SYN-Request
Count
This is the rate of new TCP half-open sessions per
second that causes the firewall to
start deleting half-open sessions. When the rate of new connection attempts rises
above this number, the Router deletes half-open sessions as required to
accommodate new connection attempts.
UDP Packet Count This is the rate of new UDP half-open sessions per second that causes the firewall
to start deleting half-open sessions. When the rate of new connection attempts
rises above this number, the Router deletes half-open sessions as required to
accommodate new connection attempts.
ICMP Echo-Request
Count
This is the rate of new ICMP Echo-Request half-open sessions per second that
causes the firewall to start deleting half-open sessions. When the rate of new
connection attempts rises above this number, the Router deletes half-open
sessions as required to accommodate new connection attempts.
ICMP Redirect Select Enab
le to monitor for and block ICMP redirect attacks.
An ICMP redirect attack is one where forge
d ICMP redirect messages can force the
client device to route packets for certain connections through an attacker’s host.
DoS Log(Log Level:
D
EBUG)
Select Enable to log DoS attacks.