Firewall > Advanced - SonicWALL SonicOS Enhanced 2.2 Administrator's Manual

Sonicwall internet security appliance
Table of Contents

Advertisement

Firewall > Advanced
Click Advanced under Firewall. The Advanced Rule Options page is displayed.
Detection Prevention
Enable Stealth Mode
By default, the SonicWALL responds to incoming connection requests as either "blocked" or "open". If you
enable Stealth Mode, your SonicWALL does not respond to blocked inbound connection requests.
Stealth Mode makes your SonicWALL essentially invisible to hackers.
Randomize IP ID
Select Randomize IP ID to prevent hackers using various detection tools from detecting the presence of
a SonicWALL appliance. IP packets are given random IP IDs which makes it more difficult for hackers to
"fingerprint" the SonicWALL appliance.
Dynamic Ports
Enable support for Oracle (SQLNet) - Select if you have Oracle applications on your network.
Enable support for Windows Messenger - Select this option to support special SIP messaging
used in Windows Messenger on the Windows XP.
Enable SIP Transformations - Select this option to transform SIP messaging from LAN (trusted to
WAN (untrusted). You need to check this setting when you want the SonicWALL to do the SIP trans-
formation. If your SIP proxy is located on the public (WAN) side of the SonicWALL and SIP clients are
on the LAN side, the SIP clients by default embed/use their private IP address in the SIP/Session Def-
inition Protocol (SDP) that are sent to the SIP proxy, hense these messages are not changed and the
SIP proxy does not know how to get back to the client behind the SonicWALL. Selecting Enable SIP
Transformations enables the SonicWALL to go through each SIP message and change the private
IP address and assigned port. Enable SIP Transformation also controls and opens up the RTP/
RTCP ports that need to be opened for the SIP session calls to happen. NAT translates Layer 3 ad-
dresses but not the Layer 5 SIP/SDP addresses, which is why you need to select Enable SIP Trans-
formations to transform the SIP messages. It's recommended that you turn on Enable SIP
Firewall Page 91

Advertisement

Table of Contents
loading

Table of Contents