initiating the connection then responds with an ACK packet,
and the connection is established. If the destination host is not
waiting for a connection on the specified port, it responds with
an RST packet. Most system logs do not log completed
connections until the final ACK packet is received from the
source.
Sending other types of packets that do not follow this
sequence can elicit useful responses from the target host,
without causing a connection to be logged. This is known as a
TCP half scan, or a stealth scan, because it does not generate
a log entry on the scanned host.
Check or un-check this option to enable or disable protection
against such attacks. The Smurf attack is a way of generating
a lot of computer network traffic to a victim host. That is, it is a
type of denial-of-service attack. Specifically, it floods a target
system via spoofed broadcast ping messages.
11.6.3.2 Access DoS Configuration Page
Log into Configuration Manager as admin, click the Firewall menu and then click
the Setting submenu. The DoS Configuration page displays, as shown in Figure
11.12.
11.6.3.3 Configuring DoS Settings
By default, most DoS protection against all supported attack types are disabled.
Figure 11.12 shows the default configuration for DoS settings. You may check or
uncheck the ―Enable DoS Check‖ to enable/disable the DoS check function. You
may check or un-check individual type of attack defense to disable or enable
protection against that specific type of attack.
Figure 11.12. DoS Configuration Page
11.6.4 Configuring Schedule
With this option you can configure access Schedule records for eventual
association with ACL rules. ACL rules associated with a Schedule record will be
active only during the scheduled period. If the ACL rule denies HTTP access
during 10:00hrs to 18:00hrs, then before 10:00hrs and after 18:00hrs the HTTP
traffic will be permitted to pass through. One Schedule record can contain up to
three time periods. For example:
Office hours on weekdays (Mon-Fri) can have the following periods:
Pre-lunch period between 9:00 and 13:00 Hrs
Post-lunch period between 14:00 and 18:30 Hrs
Office hours on weekends (Saturday-Sunday) can have the following periods:
9:00 to 12:00 Hrs
Such varying time periods can be configured into a single Schedule record.
Access rules can be activated based on these time periods.
Commentaires sur ces manuels