How to configure ADP block IP time period?






Background and Scenario:
Could it be possible to limit the tries from a certain IP to a port forward on the USG FLEX series? For example, someone that sends a DOS to an opened port, if he tries 5 times in a short amount of time, that is blocked for 1 hour.
Answer:
You could configure the block period to 3600 seconds on the ADP profile, as below:
Therefore, if the firewall detects there are ADP events, and will block the suspicious source IP.
Please refer to the below description of Block Period: "Specify for how many seconds the Zyxel Device blocks all packets from being sent to the victim (destination) of a detected anomaly attack. Flood Detection applies blocking to the destination IP address and Scan Detection applies blocking to the source IP address."
Categories
- All Categories
- 431 Beta Program
- 2.6K Nebula
- 164 Nebula Ideas
- 112 Nebula Status and Incidents
- 6K Security
- 360 USG FLEX H Series
- 292 Security Ideas
- 1.5K Switch
- 78 Switch Ideas
- 1.2K Wireless
- 42 Wireless Ideas
- 6.6K Consumer Product
- 262 Service & License
- 407 News and Release
- 87 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.9K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 83 Security Highlight