beautypg.com

ZyXEL Communications 802.11g Wireless ADSL2+ 4-port VoIP IAD P-2602HWNLI User Manual

Page 230

background image

P-2602HWNLI User’s Guide

230

Chapter 14 Firewall Configuration

One Minute High

This is the rate of new half-open sessions that causes the firewall to start deleting

half-open sessions. When the rate of new connection attempts rises above this

number, the ZyXEL Device deletes half-open sessions as required to

accommodate new connection attempts.
For example, if you set the one minute high to 100, the ZyXEL Device starts

deleting half-open sessions when more than 100 session establishment attempts

have been detected in the last minute. It stops deleting half-open sessions when

the number of session establishment attempts detected in a minute goes below the

number set as the one minute low.

Maximum

Incomplete Low

This is the number of existing half-open sessions that causes the firewall to stop

deleting half-open sessions. The ZyXEL Device continues to delete half-open

requests as necessary, until the number of existing half-open sessions drops below

this number.

Maximum

Incomplete High

This is the number of existing half-open sessions that causes the firewall to start

deleting half-open sessions. When the number of existing half-open sessions rises

above this number, the ZyXEL Device deletes half-open sessions as required to

accommodate new connection requests. Do not set Maximum Incomplete High

to lower than the current Maximum Incomplete Low number.
For example, if you set the maximum incomplete high to 100, the ZyXEL Device

starts deleting half-open sessions when the number of existing half-open sessions

rises above 100. It stops deleting half-open sessions when the number of existing

half-open sessions drops below the number set as the maximum incomplete low.

TCP Maximum

Incomplete

This is the number of existing half-open TCP sessions with the same destination

host IP address that causes the firewall to start dropping half-open sessions to that

same destination host IP address. Enter a number between 1 and 256. As a

general rule, you should choose a smaller number for a smaller network, a slower

system or limited bandwidth.

Action taken when

the TCP Maximum

Incomplete

threshold is

reached.

Delete the oldest

half open session

when new

connection

request comes

Select this radio button to clear the oldest half open session when a new

connection request comes.

Deny new

connection

request for

Select this radio button and specify for how long the ZyXEL Device should block

new connection requests when TCP Maximum Incomplete is reached.
Enter the length of blocking time in minutes (between 1 and 256).

Apply

Click Apply to save your changes to the ZyXEL Device.

Cancel

Click Cancel to begin configuring this screen afresh.

Table 81 Firewall: Threshold (continued)

LABEL

DESCRIPTION