Welcome, Guest. Please login or register.
March 19, 2010, 01:30:23 PM

Login with username, password and session length

372901 Posts
41365 Topics
94024 Members

Latest Member: warren.mcknight

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Archived Boards
| |-+  Discontinued Products
| | |-+  Comodo Firewall
| | | |-+  Help for v2
| | | | |-+  SYN-attack and emergency mode
« previous next »
Pages: [1] Go Down Print
Author Topic: SYN-attack and emergency mode  (Read 1348 times)
Shadowd
Newbie
*
Offline Offline

Posts: 1


« on: June 23, 2008, 07:05:05 AM »

Hello!

I Have a ddos syn-attack and Comodo goes to emergency mode. I use COMODO to protect my webserver. How can I disable emergency mode? How to adjust Comodo settings to not block all incoming ports when attack is observed. Is there any solution to stay ports open and block atackers IPs? Huh
Logged
grue155
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1172



« Reply #1 on: June 23, 2008, 02:05:41 PM »

Welcome to the forums, Shadowd

In v2.4, you can't really disable emergency mode. You can control it to some degree. Click Security -> Advanced, Advanced Attack Detection - Configure, and at the very bottom is the duration of emergency mode. The default is 120 seconds. I don't know if 0 would turn it off, but setting for 1 to 5 seconds would be a good approximation.

It's not possible to do that DDoS detection by port number, as it's timing the volume of traffic that comes in. You can tweak the duration numbers some, but that's the limit of CFP v2.4 capability. CFP v3 is not that different, so the prospect of an upgrade wouldn't gain you much in this instance.
Logged
gibran
Average User
Comodo's Hero
*****
Offline Offline

Posts: 5063


A bad workman always blames his tools


« Reply #2 on: June 23, 2008, 04:02:59 PM »

Is there any solution to stay ports open and block atackers IPs? Huh

I guess it's not easy like it seems. Syn attacks usually have spoofed Source IP so blocking those IPs could cause to deny connection from legit sources (this could actually facilitate the attacker purpose) as I guess it is also unlikely that only one fake IP is used to carry on such attacks.
Logged

"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."- Douglas Adams
Tags: syn-attack 
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in -0 seconds with 18 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com