EasyManuals Logo

NETGEAR FVS318G - ProSafe Gigabit VPN Firewall Data Sheet Router User Manual

NETGEAR FVS318G - ProSafe Gigabit VPN Firewall Data Sheet Router
180 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #72 background imageLoading...
Page #72 background image
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
4-20 Firewall Protection and Content Filtering
1.1 November, 2009
2. Check the boxes for the Attack Checks you wish to monitor. The various types of attack
checks are listed and defined below.
3. Click Apply to save your settings.
The various types of attack checks listed on the Attack Checks screen are:
WAN Security Checks
Respond To Ping On Internet Ports—By default, the VPN firewall does not respond to
an ICMP Echo (ping) packet coming from the Internet or WAN side. We recommend that
you leave this option disabled to prevent hackers from easily discovering the VPN firewall
via a ping, but it can be enabled as a diagnostic tool for connectivity problems.
Enable Stealth Mode—In stealth mode, the VPN firewall will not respond to port scans
from the WAN or Internet, which makes it less susceptible to discovery and attacks.
Block TCP Flood. A SYN flood is a form of denial of service attack in which an attacker
sends a succession of SYN requests to a target system. When the system responds, the
attacker doesn’t complete the connection, thus saturating the server with half-open
connections. No legitimate connections can then be made.
When blocking is enabled, the VPN firewall will limit the lifetime of partial connections
and will be protected from a SYN flood attack.
LAN Security Checks
Block UDP flood—A UDP flood is a form of denial of service attack in which the
attacking machine sends a large number of UDP packets to random ports to the victim
host. As a result, the victim host will check for the application listening at that port, see
that no application is listening at that port, and reply with an ICMP Destination
Unreachable packet.
When the victimized system is flooded, it is forced to send many ICMP packets,
eventually making it unreachable by other clients. The attacker may also spoof the IP
address of the UDP packets, ensuring that the excessive ICMP return packets do not reach
him, making the attacker’s network location anonymous.
If flood checking is enabled, the VPN firewall will not accept more than 20 simultaneous,
active UDP connections from a single computer on the LAN.
Disable Ping Reply on LAN Ports. To prevent the VPN firewall from responding to Ping
requests from the LAN, click this checkbox.

Table of Contents

Other manuals for NETGEAR FVS318G - ProSafe Gigabit VPN Firewall Data Sheet Router

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the NETGEAR FVS318G - ProSafe Gigabit VPN Firewall Data Sheet Router and is the answer not in the manual?

NETGEAR FVS318G - ProSafe Gigabit VPN Firewall Data Sheet Router Specifications

General IconGeneral
ModelFVS318G
CategoryNetwork Router
VPN Tunnels25
VPN Throughput25 Mbps
VPN ProtocolsIPSec, PPTP, L2TP
Humidity90% maximum relative humidity, non-condensing
WAN Ports1
LAN Ports8
Weight1.4 kg (3.1 lb)
Firewall SecuritySPI, DoS
Flash Memory8 MB
Operating Temperature0° to 40°C
Storage Temperature-20° to 70°C

Related product manuals