Nokia IP60 User Manual page 293

Security appliance
Hide thumbs Also See for IP60:
Table of Contents

Advertisement

In this field...
Do this...
Maximum time for
Type the maximum amount of time in seconds after which a TCP handshake
completing the
is considered incomplete.
handshake
The default value is 10 seconds.
Protect external
Specify whether SynDefender should be enabled for external (WAN)
interfaces only
interfaces only, by selecting one of the following:
Disabled. Enable SynDefender for all the firewall interfaces. This
is the default.
Enabled. Enable SynDefender for external interfaces only.
Sequence Verifier
The IP60 appliance examines each TCP packet's sequence number and checks whether it matches a TCP
connection state. You can configure how the appliance handles packets that match a TCP connection in
terms of the TCP session but have incorrect sequence numbers.
Table 72: Strict TCP
In this field...
Do this...
Action
Specify what action to take when TCP packets with incorrect sequence
numbers arrive, by selecting one of the following:
Block. Block the packets.
None. No action. This is the default.
Track
Specify whether to log TCP packets with incorrect sequence numbers, by
selecting one of the following:
Log. Log the packets. This is the default.
None. Do not log the packets.
Chapter 13: Using SmartDefense
SmartDefense Categories
293

Advertisement

Table of Contents
loading

Table of Contents