Advanced Settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.40 Locally Managed Administration Guide | 142
SSL Inspection
Attribute
Description
Validate Expiration
Indicates if the SSL inspection mechanism will drop connections that
present an expired certificate.
Validate
unreachable CRL
Indicates if the SSL inspection mechanism will drop connections that
present a certificate with an unreachable CRL.
Validate untrusted
certificates
Indicates if the SSL inspection mechanism will drop connections that
present an untrusted server certificate.
Table: SSL Inspection Attributes (continued)
Stateful
Inspection
Attribute
Description
Accept out of
state TCP
packets
Indicates if TCP packets which are not consistent with the current state of the
TCP connection are dropped (when set to 0) or accepted (when set to any
other value).
Accept
stateful ICMP
errors
Accept ICMP error packets which refer to another non-ICMP connection (for
example, to an ongoing TCP or UDP connection) that was accepted by the
Rule Base.
Accept
stateful ICMP
replies
Accept ICMP reply packets for ICMP requests that were accepted by the
Rule Base.
Accept
stateful UDP
replies for
unknown
services
Specifies if UDP replies are to be accepted for unknown services. In each
UDP service object it is possible to configure whether UDP replies for it are
accepted if the service is matched on a rule which accepts traffic. This
parameter refers to all connections which are not covered by the service
objects.
Accept
stateful other
IP protocols
replies for
unknown
services
Accept stateful other IP protocols replies for unknown services. In each
service object it is possible to configure whether replies for it are accepted if
the service is matched on a rule which accepts traffic. This parameter refers
to all no TCP/UDP connections which are not covered by the service objects.
Allow LAN-
DMZ DPI
Allow Deep Packet Inspection in traffic between internal networks and the
DMZ network.
Note - DMZ is not supported in 1530 / 1550 appliances.
Allow LAN-
LAN DPI
Allow Deep Packet Inspection in traffic between internal networks.
Table: Stateful Inspection Attributes