Cisco PIX 520 - PIX Firewall 520 Online Help Manual page 157

User guide
Hide thumbs Also See for PIX 520 - PIX Firewall 520:
Table of Contents

Advertisement

Hosts/Networks>Add> Static NAT Options
In the Static NAT Options dialog box, you can configure the advanced features associated with the selected
static NAT rule.
The following sections are included in this Help topic:
Field Descriptions
Configuring Advanced Static NAT Rule Options
Field Descriptions
The Static NAT Options dialog box displays the following fields:
Maximum Connection—Identifies the maximum number of simultaneous TCP connections that are
permitted at one time through the static NAT. The default value is 0, which indicates an unlimited number
of simultaneous TCP connections are permitted. To change the default value, enter the maximum number
of TCP connections in the Maximum Connection box.
Embryonic Limit—Identifies the embryonic connection limit to prevent TCP_SYN flood attacks. An
embryonic connection is a TCP connection that is initiated but has not yet completed. Every TCP
connection is embryonic until the TCP three-way handshake is completed, at which point the PIX Firewall
allows for an exchange of data between the given client and server. The default value is 0, which means
unlimited embryonic connections are permitted. To change the default value, enter the maximum number
of embryonic connections in the Embryonic Limit box.
Randomize Sequence Number—Instructs the PIX Firewall to randomize TCP sequence numbers to
minimize the risk of initial sequence number prediction attacks. By default, the Randomize Sequence
Number check box is selected. Clear this check box only if you are using another inline firewall that
randomizes TCP sequence numbers.
Configuring Advanced Static NAT Rule Options
Follow these steps to configure the advanced options for a static NAT rule:
1.
To define advanced options for a static NAT rule, click Advanced in the Create host/network>NAT
(Network Address Translation) dialog box. The Static NAT Options dialog box appears.
2.
To specify the maximum number of simultaneous connections that can use this translation rule, enter the
number in the Maximum Connection box. The PIX Firewall unit enforces this value against new session
requests.
3.
To specify the maximum number of simultaneous embryonic links that can use this translation rule, enter

Advertisement

Table of Contents
loading

This manual is also suitable for:

Pix device manager 1.1

Table of Contents