SmartDefense Categories
Chapter 13: Using SmartDefense
293
In this field…
Do this…
Maximum time for
completing the
handshake
Type the maximum amount of time in seconds after which a TCP handshake
is considered incomplete.
The default value is 10 seconds.
Protect external
interfaces only
Specify whether SynDefender should be enabled for external (WAN)
interfaces only, by selecting one of the following:
Disabled.
Enable SynDefender for all the firewall interfaces. This
is the default.
Enabled.
Enable SynDefender for external interfaces only.
Sequence Verifier
The IP60 appliance examines each TCP packet's sequence number and checks whether it matches a TCP
connection state. You can configure how the appliance handles packets that match a TCP connection in
terms of the TCP session but have incorrect sequence numbers.
Table 72: Strict TCP
In this field… Do this…
Action
Specify what action to take when TCP packets with incorrect sequence
numbers arrive, by selecting one of the following:
Block.
Block the packets.
None.
No action. This is the default.
Track
Specify whether to log TCP packets with incorrect sequence numbers, by
selecting one of the following:
Log.
Log the packets. This is the default.
None.
Do not log the packets.
Summary of Contents for IP60 - Security Appliance
Page 1: ...Part No N450000643 Rev 001 Published February 2008 Nokia IP60 Security Appliance User Guide ...
Page 4: ...4 Nokia IP60 Security Appliance User Guide ...
Page 10: ......
Page 12: ......
Page 38: ......
Page 58: ......
Page 108: ......
Page 268: ......
Page 482: ......