Network Tab
Revised 2017-08-31
Firewall
Drawing No. LP0997-C
- 78 -
Sixnet
®
Series SN/RAM
®
6000 & RAM 9000 Software Manual
Allow NAT-Traversal (Required):
Specify whether to allow data on UDP port 4500 on untrusted interface. The
recommended setting for this field is
Yes
.
Note:
This is necessary if you are planning to run any IPSec tunnels through our device. This would
support a unit behind a trusted interface to make an IPSec connection to a host beyond an
untrusted interface.
Force Fragmentation:
When other hosts behind us send IP packets with the Don't Fragment (DF) bit set,
enabling this option will clear the DF-bit before forwarding the packet. This allows upstream routers to fragment
the packets if smaller MTUs are encountered along the way, but performance may be impacted for
fragmentation and reassembly. If the DF-bit is set, then the packet will be dropped when smaller MTUs are
encountered. This is useful if a mis-configured router is preventing PMTU discovery from operating properly.
The recommended setting for this field is
No
.
Packet Drop Logging:
This option controls the logging level of common packet drops. These messages
normally appear in syslog. The three rate options are:
Normal:
2 messages per second max
Quieter:
10 messages per minute max
Silent:
No messages are logged.
Trusted
Interfaces
Identifies the trusted (internal) interface. Traffic from this interface will be permitted outbound. Default is “WAN/
eth0”.
Click on the
Add
button for Trusted Interfaces and the following dialog window appears:
Interface:
Choose an interface from the drop-down list provided. You may add as many interfaces as exist on
the device. Each selection must be unique.
Trusted interfaces will not block traffic to/from devices connected to that interface. Filter Rules are the only
rules that will control traffic on these interfaces.