Lancom-systems LCOS 3.50 Manuel d'utilisateur Page 165

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 346
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 164
Chapter 8: Firewall LANCOM Reference Manual LCOS 3.50
165
Firewall
8.5.2 Configuration of DoS blocking
LANconfig
Parameters against DoS attacks are set in the LANconfig in the configuration
tool 'Firewall/QoS' on the register card 'DoS':
In order to drastically reduce the susceptibility of the network for DoS
attacks in advance, packets from distant networks may be only
accepted, if either a connection has been initiated from the internal
network, or the incoming packets have been accepted by an explicit
filter entry (source: distant network, destination: local area network).
This measure already blocks a multitude of attacks.
For all permitted accesses explicitly connection state, source addresses and
correctness of fragments are tracked in a LANCOM. This happens for incoming
and for outgoing packets, since an attack could be started also from within
the local area network.
This part is configured centrally in order not to open a gate for DoS attacks by
incorrect configuration of the Firewall. Apart from specifying the maximum
number of half-open connections, fragment action and possible notification
mechanisms, also these more extensive possibilities of reaction exist:
Vue de la page 164
1 2 ... 160 161 162 163 164 165 166 167 168 169 170 ... 345 346

Commentaires sur ces manuels

Pas de commentaire