Custom Service Timeouts; Path Mtu Discovery - D-Link NetDefendOS User Manual

Network security firewall
Hide thumbs Also See for NetDefendOS:
Table of Contents

Advertisement

4.
Select my_second_service from Available and press include
5.
Click OK

3.3.6. Custom Service Timeouts

Any service can have its custom timeouts set. These can also be set globally in NetDefendOS but it
is more usual to change these values individually in a custom service.
The timeout settings that can be customized are as follows:
Initial Timeout
This is the time allowed for a new connection to be open.
Establish (Idle) Timeout
If there is no activity on a connection for this amount of time then it is considered to be
closed and is removed from the NetDefendOS state table. The default setting for this time
with TCP/UDP connections is 3 days.
Closing Timeout
The is the time allowed for the connection to be closed.
The administrator must make a judgment as what the acceptable values should be for a
particular protocol. This may depend, for example, on the expected responsiveness of servers to
which clients connect.

3.3.7. Path MTU Discovery

Overview
Path MTU Discovery (also shortened to just MTU discovery in this section) is a method by which
the MTU size of either IPv4 or IPv6 packets sent across the Internet can be adjusted to meet the
MTU limits of traversed network equipment and thus avoiding the need for fragmentation. When
a packet exceeds a piece of network equipment's next-hop MTU limit and the packet's DF (Don't
Fragment) flag is set, ICMP messages are sent back to the sender of the packet to resend with an
adjusted MTU size. This is defined by RFC 1191 (for IPv4) and RFC 1981 (for IPv6).
Implementation in NetDefendOS
The NetDefendOS path MTU discovery implementation allows both of the following two
functions:
The ICMP messages involved in MTU discovery between two external pieces of network
equipment can be forwarded.
NetDefendOS will send MTU discovery ICMP messages back to the sender if the DF (Don't
Fragment) flag is set and the packet size is larger than the MTU set for NetDefendOS's
outgoing interface (the next-hop MTU).
174
Chapter 3: Fundamentals

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents