77
Enable SYN flood protection
Makes router more resistant to SYN flood attacks.
Set rate limit (packets/second) for SYN packets above
which the traffic is considered a flood.
Set burst limit for SYN packets above which the traffic is
considered a flood if it exceeds the allowed rate.
Enable the use of SYN cookies (particular choices of
initial TCP sequence numbers by TCP servers).
7.6.6.2 Remote ICMP requests
Attackers are using ICMP echo request packets directed to IP broadcast addresses from remote locations to
generate denial-of-service attacks.
Blocks remote ICMP echo-request type
Enable ICMP echo-request limit in selected period
Select in what period limit ICMP echo-request
Maximum ICMP echo-request during the period
Indicating the maximum burst before the above limit
kicks in.
7.6.6.3 SSH Attack Prevention
Prevent SSH (Allows a user to run commands on a machine's command prompt without them being physically
present near the machine.) attacks by limiting connections in defined period.