ZyXEL Communications 802.11g Wireless ADSL2+ 4-port VoIP IAD P-2602HWNLI User Manual
Page 230

P-2602HWNLI User’s Guide
230
Chapter 14 Firewall Configuration
One Minute High
This is the rate of new half-open sessions that causes the firewall to start deleting
half-open sessions. When the rate of new connection attempts rises above this
number, the ZyXEL Device deletes half-open sessions as required to
accommodate new connection attempts.
For example, if you set the one minute high to 100, the ZyXEL Device starts
deleting half-open sessions when more than 100 session establishment attempts
have been detected in the last minute. It stops deleting half-open sessions when
the number of session establishment attempts detected in a minute goes below the
number set as the one minute low.
Maximum
Incomplete Low
This is the number of existing half-open sessions that causes the firewall to stop
deleting half-open sessions. The ZyXEL Device continues to delete half-open
requests as necessary, until the number of existing half-open sessions drops below
this number.
Maximum
Incomplete High
This is the number of existing half-open sessions that causes the firewall to start
deleting half-open sessions. When the number of existing half-open sessions rises
above this number, the ZyXEL Device deletes half-open sessions as required to
accommodate new connection requests. Do not set Maximum Incomplete High
to lower than the current Maximum Incomplete Low number.
For example, if you set the maximum incomplete high to 100, the ZyXEL Device
starts deleting half-open sessions when the number of existing half-open sessions
rises above 100. It stops deleting half-open sessions when the number of existing
half-open sessions drops below the number set as the maximum incomplete low.
TCP Maximum
Incomplete
This is the number of existing half-open TCP sessions with the same destination
host IP address that causes the firewall to start dropping half-open sessions to that
same destination host IP address. Enter a number between 1 and 256. As a
general rule, you should choose a smaller number for a smaller network, a slower
system or limited bandwidth.
Action taken when
the TCP Maximum
Incomplete
threshold is
reached.
Delete the oldest
half open session
when new
connection
request comes
Select this radio button to clear the oldest half open session when a new
connection request comes.
Deny new
connection
request for
Select this radio button and specify for how long the ZyXEL Device should block
new connection requests when TCP Maximum Incomplete is reached.
Enter the length of blocking time in minutes (between 1 and 256).
Apply
Click Apply to save your changes to the ZyXEL Device.
Cancel
Click Cancel to begin configuring this screen afresh.
Table 81 Firewall: Threshold (continued)
LABEL
DESCRIPTION