Nokia IPSO 4.0 manual Miscellaneous Security Settings, To set TCP flag combinations

Models: IPSO 4.0

1 510
Download 510 pages 5.58 Kb
Page 349
Image 349

Miscellaneous Security Settings

The Miscellaneous Security Settings page under Configuration > Security and Access allows you to change the handling of TCP packets. The default behavior is for IPSO to drop TCP packets that have both SYN and FIN bits set. This behaviour addresses a CERT advisory. For more information on that advisory, go to http://www.kb.cert.org/vul/id/464133.

You must change the default configuration if you want your Nokia platform to accept packets that have both the SYN and FIN bits set. Complete the following procedure to configure your platform to accept packets that have both SYN and FIN bits set.

To set TCP flag combinations

1.Click Miscellaneous Security Settings under Configuration > Security and Access in the tree view.

2.Select On next to Allow TCP/IP(rfc1644) mode (SYN-FIN together).

Select Off to return to the default configuration if you have enabled your platform to accept packets that have both SYN and FIN bits set..

3.Click Apply

4.Click Save to make your change permanent

Nokia Network Voyager for IPSO 4.0 Reference Guide

349

Page 349
Image 349
Nokia IPSO 4.0 manual Miscellaneous Security Settings, To set TCP flag combinations