Peplink firewall option – Intrusion detection

Most of us will be familiar with Peplink’s intrusion detection feature, but when is the router actually triggered to block certain traffic?

As shown in the information visible when selecting the HELP icon, when Intrusion detection is enabled the Peplink blocks abnormal packets, such as TCP packets with all flags enabled (Malformed XMAS packet). It block suspicious traffic, such as large volumes of new TCP SYN packets (SYN Flood). These new TCP SYN packets generated by the suspicious IP address will be blocked until the “SYN Flood” has stopped.

But what traffic is blocked exactly? The actual triggers are the following:

  • Rapidly generated TCP sessions with SYNC flag set only.
  • Rapidly generated ICMP sessions.
  • A TCP packet without any flag set.
  • A TCP packet with flag FIN, URG and PSH only.
  • A TCP packet with flag SYN, ACK, FIN, RST, URG and PSH.
  • A TCP packet with flag SYN, ACK, FIN, RST and URG only.
  • A TCP packet with flag SYN and RST is set.
  • A TCP packet with flag SYN and FIN is set.
Peplink Ninja
Peplink Ninja is an independent Peplink news aggregation and commentary site, providing access to all the latest Peplink & Pepwave company, partner and product news.

More from author

Related posts

Advertisment

Latest posts

Peplink Cellular Routers Fulfill Connectivity Criteria for MSPs

In the realm of selecting vendor solutions, MSPs and end users diverge in their criteria, with MSPs catering to a broader spectrum...

Peplink’s 5G Routers Transforming Smart Warehouses with Indoor 5G

Leveraging 5G routers for indoor 5G connectivity is the cornerstone of creating smart warehouses, playing a pivotal role in the success of...

Top Choice for 5G Routers in Security Systems: Peplinks Indoor 5G Solution

Selecting the right 5G router for security systems is now a complex endeavor, driven by elevated expectations for video security and access...

Want to stay up to date with the latest Peplink news?

Get all the very latest news and regular Peplink SDWAN updates.

Top