Appendix
A
Advanced system settings
This chapter includes the following topics:
■
Configuring advanced options
The security gateway includes a set of configurable options that modify its behavior. These advanced
options are normally used to fine tune the behavior of one or more of the security gateway’s specific
features. They are also commonly used by Symantec Technical Support as a method of generating
more verbose log messages to help diagnose and troubleshoot issues.
Caution:
You should not add advanced options unless directed to do so by Symantec Technical Support.
Incorrectly entering advanced options can cause performance problems.
shows some of the advanced options already in use in the advanced options section found in
System > Administration > Advanced Options. The remaining options are available for use, but are not
enabled by default.
Table A-1
Advanced options
Option name
Description
blacklistd.blacklist_time
Period of time (in minutes) that an IP address remains on the
blacklist.
The default value is 1440 minutes (24 hours).
blacklistd.excessive_replay_timeout
Period of time to ignore the client when the thresholds for
blcklistd.max_replays or blacklistd.replay_sample_period are
reached.
The default value is 0.
blacklistd.max_replays
Limit of the maximum number of re-acknowledgements (NAKs) to
accept from the client before the security gateway considers that the
client is using a replay attack.
The default value is 5.
blacklistd.replay_sample_period
Alerts the blacklist daemon that a possible replay attack is underway
if the period of time since the last packet from the client is greater
than the value defined.
The default value is 1.
connection_rate.block_time
Period of time (in seconds) to block an IP address if the number of
connections from that source IP address exceeds the limit defined by
connection_rate.limit
The default value is 3600.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...