Configure security settings
Firewall
Digi TransPort WR Routers User Guide
702
Stateful inspection
The Digi routing code stack contains a sophisticated scripted stateful firewall and route inspection
engine. Stateful inspection is a powerful tool allowing the router to keep track of a TCP/UDP or ICMP
session and match packets based on the state of the connection on which they are being carried. In
addition to providing sophisticated firewall functionality, the SF/RI engine also provides a number
of facilities for tracking the health of routes, marking dead routes as being Out Of Service (OOS) and
creating rules for the automatic status checking of routes previously marked as OOS (for use in
multilevel backup/restore scenarios).
You can use the firewall to put interfaces into an OOS state, and control how the interfaces return to
service. When an interface goes OOS, all routes configured to use that interface will have their route
metric set to
16
(the maximum value), meaning that some other route with a lower metric will be
selected.
When a firewall stateful inspection rule expires, a decision is made as to whether the traffic being
allowed to pass by this rule completed successfully or not. For example, if the stateful rule monitors
SYN
and
FIN
packets in both directions for a TCP socket then that rule will expire successfully.
However, if
SYNs
are seen to pass in one direction but no
SYNs
pass in the other direction, the
stateful rule will expire and the router will tag this as a failure.
Conditions tagging a stateful rule as a failure
The following conditions tag a stateful rule as a failure:
▪
Packets have only passed in one direction.
▪
10
packets have passed in one direction with no return packets (for TCP the packets must also
be re-transmits) All of these features depend upon the stateful inspection capabilities of the
Firewall engine which are explained below.
The [inspect] field
The
[inspect]
field takes the following format:
inspect = [“inspect-state” {“oos” {interface-name¦logical-name} secs
{t=secs} {c=count} {d=count}} {r=“ping”¦“tcp”{,secs{secs}}} {rd=x}
{dt=secs}{stat}]
You can use the
[inspect]
field on its own or with an optional
oos
(Out Of Service) parameter.
Summary of Contents for TransPort WR11
Page 1: ...User Guide Digi TransPort WR Routers ...
Page 650: ...Configure system settings NTP parameters Digi TransPort WR Routers User Guide 650 ...
Page 661: ...Configure system settings General system parameters Digi TransPort WR Routers User Guide 661 ...
Page 662: ...Configure system settings General system parameters Digi TransPort WR Routers User Guide 662 ...
Page 663: ...Configure system settings General system parameters Digi TransPort WR Routers User Guide 663 ...
Page 682: ...Configure Remote Management SNMP parameters Digi TransPort WR Routers User Guide 679 ...
Page 683: ...Configure Remote Management SNMP parameters Digi TransPort WR Routers User Guide 680 ...
Page 813: ...Manage networks and connections Top Talkers Digi TransPort WR Routers User Guide 808 ...
Page 814: ...Manage networks and connections Top Talkers Digi TransPort WR Routers User Guide 809 ...
Page 815: ...Manage networks and connections Top Talkers Digi TransPort WR Routers User Guide 810 ...
Page 816: ...Manage networks and connections Top Talkers Digi TransPort WR Routers User Guide 811 ...
Page 817: ...Manage networks and connections Top Talkers Digi TransPort WR Routers User Guide 812 ...
Page 818: ...Manage networks and connections Top Talkers Digi TransPort WR Routers User Guide 813 ...
Page 855: ...Device administration Reboot the router Digi TransPort WR Routers User Guide 844 ...