Motorola 7.7.4 manual Set security state-insp tcp-timeout 30, 262

Models: 7.7.4

1 351
Download 351 pages 50.78 Kb
Page 262
Image 262

Stateful Inspection

Stateful inspection options are accessed by the security state-insptag.

set security state-insp [ ip-ppp dsl ] vccn option [ off on ] set security state-insp ethernet [ A B ] option [ off on ]

Sets the stateful inspection option off or on on the specified interface. This option is dis- abled by default. Stateful inspection prevents unsolicited inbound access when NAT is dis- abled.

set security state-insp [ ip-ppp dsl ] vccn default-mapping [ off on ]

set security state-insp ethernet [ A B ] default-mapping [ off on ]

Sets stateful inspection default mapping to router option off or on on the specified inter- face.

set security state-insp [ ip-ppp dsl ] vccn tcp-seq-diff [ 0 - 65535 ]

set security state-insp ethernet [ A B ] tcp-seq-diff [ 0 - 65535 ]

Sets the acceptable TCP sequence difference on the specified interface. The TCP sequence number difference maximum allowed value is 65535. If the value of tcp-seq-diffis 0, it means that this check is disabled.

set security state-insp [ ip-ppp dsl ] vccn deny-fragments [ off on ]

set security state-insp ethernet [ A B ] deny-fragments [ off on ]

Sets whether fragmented packets are allowed to be received or not on the specified inter- face.

set security state-insp tcp-timeout [ 30 - 65535 ]

Sets the stateful inspection TCP timeout interval, in seconds.

262

Page 262
Image 262
Motorola 7.7.4 manual Set security state-insp tcp-timeout 30, 262