Network Tab
Revised 2017-08-31
TCP Global Settings
Drawing No. LP0997-C
- 112 -
Sixnet
®
Series SN/RAM
®
6000 & RAM 9000 Software Manual
There are three available options:
•
No Source validation
•
Strict Mode
: As defined in RFC3704 Strict Reverse Path, each incoming packet is tested against the
FIB and if the interface is not he best reverse path then the packet check will fail. By default failed
packets are discarded.
•
Loose Mode: As defined in RFC3704 Loose Reverse Path, each incoming packet’s source is also
tested against the FIB and if the source address is not reachable via any interface then the packet
check will fail.
Current recommended practice in RFC3704 is to enable strict mode to prevent IP spoofing from DDos attacks.
If using asymmetric routing or other complicated routing, then loose mode is recommended.
Click on the
Apply
button to save the newly entered values. To revert to the previous defaults, click on the
Revert
button.