113 
 
10.2  Firewall 
The router supports ARP attack defense, DDoS defense, IP attack defense, and WAN ping packet blocking. 
 
ARP Attack Defense: The router can defend ARP spoofing, ARP broadcast attack, and so on. 
 
DDOS Defense: DDOS attack indicates the distributed denial of service attack. The attack allows an 
attacker to exhaust the resources of a system, making the system unable to properly provide services. 
Types of DDOS attack the router can defend include ICMP flood, UDP flood, and SYN flood. 
 
IP Attack Defense: The router can intercept data packets containing the following special IP options: IP 
Timestamp Option, IP Security Option, IP Stream Option, IP Record Route Option, IP Loose Source Route 
Option, and Invalid IP Option. 
 
Block WAN Pinging: When the host on The internet pings the WAN IP of the router, the router can 
automatically neglects the Ping request to prevent exposure and defend against the external Ping 
attack. 
When one or more defense functions are enabled, the router records the attack information, such as attack time, 
type, count, attacker IP, MAC, and so on into logs, which can be viewed on the System Status > Defense Logs. 
To access the page, choose Firewall. 
 
Parameter description 
Enable ARP Attack 
Defense 
It specifies whether to enable the ARP attack defense.