
Using SmartDefense
Table 39: Packet Sanity Fields
In this field… Do this…
Action
Sp
one
•
e default.
•
ecify what action to take when a packet fails a sanity test, by selecting
of the following:
Block.
Block the packet. This is th
None.
No action.
Track
Sp
sel
following:
•
fault.
•
verification
Th
d
r length specified in the UDP header. If
the
o
Howev
gth
diff
ation sanity
check by default, performing the check but not dropping offending packets.
This is called relaxed UDP length verification.
Specify whether the NetDefend firewall should relax the UDP length
verification sanity check or not, by selecting one of the following:
•
True.
Disable relaxed UDP length verification. The NetDefend
firewall will drop packets that fail the UDP length verification
check.
•
False.
Do not disable relaxed UDP length verification. The
NetDefend firewall will not drop packets that fail the UDP length
verification check. This is the default.
ecify whether to issue logs for packets that fail the packet sanity tests, by
ecting one of the
Log.
Issue logs. This is the de
None.
Do not issue logs.
Disable relaxed
UDP length
an
e UDP length verification sanity check measures the UDP header length
compares it to the UDP heade
tw values differ, the packet may be corrupted.
er, since different applications may measure UDP header len
erently, the NetDefend firewall relaxes the UDP length verific
230
D-Link NetDefend firewall User Guide