Stateful Inspection Options

Stateful Inspection Parameters are active on a WAN interface only if you enable them on your Gateway.

Stateful Inspection: To enable stateful inspection on this WAN interface, check the checkbox.

Default Mapping to Router: This is disabled by default. This option will allow the router to respond to traffic received on this interface, for example, ICMP Echo requests.

NOTE:

If Stateful Inspection is enabled on a WAN interface Default Mapping to Router must be enabled to allow inbound VPN terminations to the router.

TCP Sequence Number Difference: Enter a value in this field. This value represents the maximum sequence number difference allowed between subsequent TCP packets. If this number is exceeded, the packet is dropped. The acceptable range is 0 – 65535. A value of 0 (zero) disables this check.

Deny Fragments: To enable this option, which causes the router to discard fragmented packets on this interface, check the checkbox.

144

Page 144
Image 144
Netopia 2200 manual Stateful Inspection Options, 144