FIREWALL

 

 

 

 

Parameter

Defaults

Description

Stateful Packet

 

This option allows you to select different

Inspection

 

application types that are using dynamic port

 

 

 

numbers. If you wish to use Stateful Packet

 

 

 

Inspection (SPI) for blocking packets, click on

 

 

 

the “Yes” radio button in the “Enable SPI and

 

 

 

Anti-DoS firewall protection” field and then

 

 

 

check the inspection type that you need, such as

 

 

 

Packet Fragmentation, TCP Connection, UDP

 

 

 

Session, FTP Service, H.323 Service, and TFTP

 

 

 

Service.

 

 

 

It is called a “stateful” packet inspection because

 

 

 

it examines the contents of the packet to

 

 

 

determine what the state of the communication

 

 

 

is, i.e. it ensures that the stated destination

 

 

 

computer has previously requested the current

 

 

 

communication. This is a way of ensuring that all

 

 

 

communications are initiated by the recipient

 

 

 

computer and are taking place only with sources

 

 

 

that are known and trusted from previous

 

 

 

interactions. In addition to being more rigorous

 

 

 

in their inspection of packets, stateful inspection

 

 

 

firewalls also close off ports until connection to

 

 

 

the specific port is requested.

 

 

 

When particular types of traffic are checked, only

 

 

 

the particular type of traffic initiated from the

 

 

 

Internal LAN will be allowed. For example, if the

 

 

 

user only checks “FTP Service” in the Stateful

 

 

 

Packet Inspection section, all incoming traffic

 

 

 

will be blocked except FTP connections initiated

 

 

 

from the local LAN.

Hacker Prevention

 

 

Feature

 

 

 

Discard Ping

Discard

Prevents a PING on the Gateway’s WAN port

 

from WAN

 

from being routed to the network.

4-43

Page 68
Image 68
SMC Networks SMC7404BRA EU manual 4-43, Parameter, Defaults, Description, Stateful Packet