SPI for the 3Com 3CR858-91Router Sceenshot

Setup Wizard LAN Settings Internet Settings Firewall SPI Special Applications Virtual Servers Client IP Filters MAC Address Filtering DMZ VPN SNMP System Tools Advanced Status and Logs Support/Feedback When the SPI (Stateful Packet Inspection) firewall feature is enabled, all packets can be blocked. SPI allows full support of different application types that are using dynamic port numbers. For the applications checked in the list below, this Router will support full operation as initiated from the local LAN. Intrusion Detection Feature SPI and Anti-DoS firewall protection: RIP defect: Discard Ping To WAN: --> Stateful Packet Inspection Packet Fragmentation: TCP Connection: UDP Session: FTP Service: H.323 Service: TFTP Service: When detected hackers attempting to access network, alert by e-mail Your E-mail Address: SMTP Server Address: POP3 Server Address: --> User name: Password: Connection Policy Fragmentation half-open wait: sec. TCP SYN wait: sec. TCP FIN wait: sec. TCP connection idle timeout: sec. UDP session idle timeout: sec. H.323 data channel idle timeout: sec. DoS Detect Criteria Total incomplete TCP/UDP sessions HIGH: session Total incomplete TCP/UDP sessions LOW: session Incomplete TCP/UDP sessions (per min) HIGH: session Incomplete TCP/UDP sessions (per min) LOW: session Maximum incomplete TCP/UDP sessions number from same host: Incomplete TCP/UDP sessions detect sensitive time period: msec. Maximum half-open fragmentation packet number from same host: Half-open fragmentation detect sensitive time period: msec. Flooding cracker block time: sec.