beautypg.com

AirLive RS-2500 User Manual

Page 193

background image

21. Anomaly Flow IP


AirLive RS-2500 User’s Manual

188

Detect Tear Drop Attack:

ar drop attacks. These are packets that are

e LAN networks and send

em.

hut down when receiving packets with the same source and

destination addresses, the same source port and destination port, and when SYN

ed. Enable this function to detect such abnormal

etected IP, because

some of these IP provide amount of services, and it is possible to be judged as the

se this function to avoid the problem.

Select this option to detect te

segmented to small packets with negative length. Some Systems treat the

negative value as a very large number, and copy enormous data into the System

to cause System damage, such as a shut down or a restart.

Filter IP Route Option:

Each IP packet can carry an optional field that specifies the replying address that

can be different from the source address specified in packet’s header. Hackers

can use this address field on disguised packets to invad

LAN networks’ data back to th

Detect Land Attack:

Some Systems may s

on the TCP header is mark

packets.

Non-detected IP:

System administrator can set up IP address to be the non-d

anomaly flow IP. We can u

After System Manager enable Anomaly Flow IP, if the RS-2500 has

detected any abnormal situation, the alarm message will appear in

Virus-infected IP or Attack Event. And if the system manager starts

ification in Settings, the device will send e-mail to

the E-mail Alert Not

alarm the system manager automatically.