DEVICE ADMINISTRATION
MultiConnect
®
rCell 100 MTR-EV3 User Guide 81
DoS Prevention
This area of the Access Configuration window engages a set of rules at the firewall that prevents Denial-of-Service
attacks by limiting the amount of new connection requests to the device.
Field Description
Enabled Enables DoS prevention.
Per Minute Allowed number of new connections per minute until
burst points are consumed. For example, if 60 new
connections are received in a minute, decrement one
burst point. If no more burst points, drop the packet.
Burst Number of allowed burst for traffic spikes. A burst
occurs when the Per Minute limit is reached. On a
period where the Per Minute limit is not reached, one
burst point is regained, up to the maximum.
Ping Limit
This area of the Access Configuration window engages a set of rules at the firewall that aims to prevent ping flood
attacks by limiting the number of ICMP requests to the device. These rules that mitigate the effects of a ping DoS
on your device do not apply if ICMP is disabled.
Field Description
Enabled Enables the Ping Limit feature.
Per Second Allowed number of pings per second before burst
points are consumed. Once burst points run out, ICMP
packets will be dropped.
Burst Number of burst points. On a period where the Per
Second limit is not reached, one burst point is regained,
up to this maximum.
Brute Force Protection
This feature tracks login attempts at the RESTFUL API level. Its purpose is to prevent Dictionary attacks that
attempt to brute force the user's password.
Field Description
Enabled Enables the Brute Force Prevention feature.
Attempts The number of failed attempts allowed before the
user's account is locked out.
Lockout Minutes The number of minutes an account is locked out before
a new login attempt will be accepted.
RADIUS Configuration
The RADIUS protocol supports authentication, user session accounting, and authorization of users to the device.
This authentication, accounting, and authorization is independent of the local users created on the device. The
user can enable Authentication, Accounting, or both options.