这是ns有dos关有关最新os的firewall设置
Denial of Service Defense
Ping of Death Attack Protection
Tear-drop Attack Protection
ICMP Fragment Protection
Large Size ICMP Packet (Size > 1024) Protection
Block Fragment Traffic
SYN-ACK-ACK Proxy Protection Threshold Connections
Source IP Based Session Limit Threshold Sessions
Destination IP Based Session Limit Threshold Sessions
其中syn攻击就是ddos攻击的最典型手段之一,其他的变量同样检查和阻挡ddos的参数,其实ddos只是dos的多机版,他对防火墙只是对于处理能力的考验,更快的cpu和更大的内存意味着更好的抵御能力!!