D-Link DFL-1660 User Manual page 104

Network security firewall
Hide thumbs Also See for DFL-1660:
Table of Contents

Advertisement

3.4.6. ARP Advanced Settings
Summary
Default: DropLog
ARP Requests
Determines if NetDefendOS will automatically add the data in ARP requests to its ARP table. The
ARP specification states that this should be done, but as this procedure can facilitate hijacking of
local connections, it is not normally allowed. Even if ARPRequests is set to "Drop", meaning that
the packet is discarded without being stored, NetDefendOS will, provided that other rules approve
the request, reply to it.
Default: Drop
ARP Changes
Determines how NetDefendOS will deal with situations where a received ARP reply or ARP request
would alter an existing item in the ARP table. Allowing this to take place may facilitate hijacking of
local connections. However, not allowing this may cause problems if, for example, a network
adapter is replaced, as NetDefendOS will not accept the new address until the previous ARP table
entry has timed out.
Default: AcceptLog
Static ARP Changes
Determines how NetDefendOS will handle situations where a received ARP reply or ARP request
would alter a static item in the ARP table. Of course, this is never allowed to happen. However, this
setting does allow you to specify whether or not such situations are to be logged.
Default: DropLog
ARP Expire
Specifies how long a normal dynamic item in the ARP table is to be retained before it is removed
from the table.
Default: 900 seconds (15 minutes)
ARP Expire Unknown
Specifies in seconds how long NetDefendOS is to remember addresses that cannot be reached. This
is done to ensure that NetDefendOS does not continuously request such addresses.
Default: 3
ARP Multicast
Determines how NetDefendOS is to deal with ARP requests and ARP replies that state that they are
multicast addresses. Such claims are usually never correct, with the exception of certain load
balancing and redundancy devices, which make use of hardware layer multicast addresses.
Default: DropLog
ARP Broadcast
Determines how NetDefendOS deals with ARP requests and ARP replies that state that they are
104
Chapter 3. Fundamentals

Advertisement

Table of Contents
loading

Table of Contents