13.6.2  

Security/Firewall/Packet Filter 
 
HG 1500 features status-dependent control filters. The status-dependent control checks are performed over "flows". A "flow" is stream of associated packets and all the error ICMPs (including path-MTU messages) that affect these packets. In TCP terms, a flow is defined on the basis of IP addresses and port numbers, and consists of both the TCP packets and all associated error ICMPs. This is similar for UDP.
DoS: HG 1500 offers protection against various Denial-of-Service attacks and other network-level attacks, such as, SYN flooding, various fragmentation attacks, TCP hijacking (different active attacks, for example, via ARP spoofing), LAND (identical source and destination IPs), so-called "Christmas trees" (all TCP flags set), etc.