Netopia 2200 manual Set security state-insp tcp-timeout 30, 276

Models: 2200

1 351
Download 351 pages 59.91 Kb
Page 276
Image 276

Stateful Inspection

Stateful inspection options are accessed by the security state-insptag.

set security state-insp [ ip-ppp dsl ] vccn option [ off on ] set security state-insp ethernet [ A B ] option [ off on ]

Sets the stateful inspection option off or on on the specified interface. This option is dis- abled by default. Stateful inspection prevents unsolicited inbound access when NAT is dis- abled.

set security state-insp [ ip-ppp dsl ] vccn default-mapping [ off on ]

set security state-insp ethernet [ A B ] default-mapping [ off on ]

Sets stateful inspection default mapping to router option off or on on the specified inter- face.

set security state-insp [ ip-ppp dsl ] vccn tcp-seq-diff [ 0 - 65535 ]

set security state-insp ethernet [ A B ] tcp-seq-diff [ 0 - 65535 ]

Sets the acceptable TCP sequence difference on the specified interface. The TCP sequence number difference maximum allowed value is 65535. If the value of tcp-seq-diffis 0, it means that this check is disabled.

set security state-insp [ ip-ppp dsl ] vccn deny-fragments [ off on ]

set security state-insp ethernet [ A B ] deny-fragments [ off on ]

Sets whether fragmented packets are allowed to be received or not on the specified inter- face.

set security state-insp tcp-timeout [ 30 - 65535 ]

Sets the stateful inspection TCP timeout interval, in seconds.

276

Page 276
Image 276
Netopia 2200 manual Set security state-insp tcp-timeout 30, 276