
27
2.2.1.4 synflood
This command can activate the SYN flood defense function. If the amount of TCP SYN
packets from the Internet exceeds the user-defined threshold value, the router will be forced to
randomly discard the subsequent TCP SYN packets within the user-defined timeout period.
enable <0/1>
threshold<value> <timeout>
threshold -s
Syntax Description
Syntax Description
enable Enter “Enable 1” to enable SYN flood defense.
Enter “Enable 0” to disable SYN flood defense.
value Enter the number of the threshold for SYN flood defense. The
range is from 0 to 65535. (default=300 packets/sec)
timeout Enter the value (greater than 5) for the time out. The unit is
second.
-s It is used for displaying the settings of current threshold.
Example
DrayTek/firewall/dos/synflood> enable 1
DrayTek/firewall/dos/synflood> threshold 320 200
DrayTek/firewall/dos/synflood> threshold -s
Firewall Dos SYN flood Threshold: 320 Packets/sec
Timeout: 200 sec
Comentarios a estos manuales