D-Link NetDefend DFL-CP310 User Manual page 249

Security vpn firewall netdefend secured by check point
Hide thumbs Also See for NetDefend DFL-CP310:
Table of Contents

Advertisement

Table 41: IP Fragments Fields
In this field...
F
orbid IP Fragments
Max Number of
Incomplete Packets
Timeout for
Discarding
Incomplete Packets
Track
Chapter 9: Setting Your Security Policy
Do this...
Specify whether all f
ragmented packets should be dropped, by selecting
one of the following:
True. Drop all fragme
False. No action.
This is the default.
Under normal circumstances, it is recommended to leave this field set to
False. Setting this field to True may disrupt Internet connectivity, because
it does not allow any fragmented packets.
Type the maximum number of fragmented packets allowed. Packets
exceeding this threshold will be dropped.
The default value is 300.
When the NetDefend firewall receives packet fragments, it waits for
additional fragments to arrive, so that it can reassemble the packet.
Type the number of seconds to wait before discarding incomplete
packets.
The default value is 10.
Specify whether to log fragmented packets, by selecting one of the
following:
Log. Log all fragmented packets.
None. Do not log the fragmented packets. This
nted packets.
Using SmartDefense
is the default.
233

Advertisement

Table of Contents
loading

This manual is also suitable for:

Netdefend dfl-cpg310Cp310 - dfl - security appliance

Table of Contents