
Wireless Firewall
Altitude
TM
4000 Series Access Point System Reference Guide
303
17
The Firewall policy allows traffic filtering at the application layer using the
Application Layer Gateway
(ALG)
feature. The Application Layer Gateway provides filters for the following common protocols:
18
Refer to the
Firewall Enhanced Logging
field to set the following parameters:
IPMAC Routing
Conflict Enable
Select this option to enable IPMAC Routing Conflict detection. This is
also known as a Hole-196 attack in the network. This feature helps to
detect if the client is sending routed packets to the correct MAC address.
IPMAC Routing
Conflict Logging
Select enable logging for IPMAC Routing Conflict detection. This feature
is enabled by default and set to Warning.
IPMAC Routing
Conflict Action
Use the drop-down menu to set the action taken when an attack is
detected. Options include Log Only, Drop Only or Log and Drop. The
default setting is Log and Drop.
DNS Snoop Entry
Timeout
Select this option and set a timeout, in seconds, for DNS Snoop Entry.
DNS Snoop Entry stores information such as Client to IP Address and
Client to Default Gateway(s) and uses this information to detect if the
client is sending routed packets to a wrong MAC address.
IP TCP Adjust MSS
Select this option and adjust the value for the maximum segment size
(MSS) for TCP segments on the router. Set a value between 472 bytes
and 1,460 bytes to adjust the MSS segment size. The default value is
472 bytes.
TCP MSS Clamping
Select this option to enable TCP MSS Clamping. TCP MSS Clamping
allows configuration for the maximum segment size of packets at a
global level.
Max Fragments/
Datagram
Set a value for the maximum number of fragments (between 2 and
8,129) allowed in a datagram before it is dropped. The default value is
140 fragments.
Max
Defragmentations/
Host
Set a value for the maximum number of defragmentations, between 1
and 16,384 allowed per host before it is dropped. The default value is 8.
Min Length Required
Select this option and set a minimum length, between 8 bytes and 1,500
bytes, to enforce a minimum packet size before being subject to
fragment based attack prevention.
IPv4 Virtual
Defragmentation
Select this option to enable IPv4 Virtual Defragmentation, this helps
prevent IPv4 fragments based attacks, such as tiny fragments or large
number of ipv4 fragments.
FTP ALG
Check the
Enable
box to allow FTP traffic through the Firewall using its
default ports. This feature is enabled by default.
TFTP ALG
Check the
Enable
box to allow TFTP traffic through the Firewall using its
default ports. This feature is enabled by default.
SIP ALG
Check the
Enable
box to allow SIP traffic through the Firewall using its
default ports. This feature is enabled by default.
Log Dropped ICMP
Packets
Use the drop-down menu to define how dropped ICMP packets are
logged. Logging can be rate limited for one log instance every 20
seconds. Options include
Rate Limited
,
All
or
None
. The default setting is
None.
Log Dropped
Malformed Packets
Use the drop-down menu to define how dropped malformed packets are
logged. Logging can be rate limited for one log instance every 20
seconds. Options include
Rate Limited
,
All
or
None
. The default setting is
None.
Enable Verbose
Logging
Select this option to enable verbose logging for dropped packets. This
setting is disabled by default.
Содержание Altitude 4000 Series
Страница 14: ...Chapter 2 Overview AltitudeTM 4000 Series Access Point System Reference Guide 14...
Страница 44: ...Chapter 4 Quick Start AltitudeTM 4000 Series Access Point System Reference Guide 44...
Страница 58: ...Chapter 5 Dashboard AltitudeTM 4000 Series Access Point System Reference Guide 58...
Страница 116: ...Chapter 6 Device Configuration AltitudeTM 4000 Series Access Point System Reference Guide 116...
Страница 205: ...Adoption Overrides AltitudeTM 4000 Series Access Point System Reference Guide 205...
Страница 218: ...Chapter 6 Device Configuration AltitudeTM 4000 Series Access Point System Reference Guide 218...
Страница 328: ...Chapter 8 Security Configuration AltitudeTM 4000 Series Access Point System Reference Guide 328...
Страница 332: ...Chapter 9 Services Configuration AltitudeTM 4000 Series Access Point System Reference Guide 332...
Страница 368: ...Chapter 9 Services Configuration AltitudeTM 4000 Series Access Point System Reference Guide 368...
Страница 380: ...Chapter 10 Management Access Policy Configuration AltitudeTM 4000 Series Access Point System Reference Guide 380...
Страница 420: ...Chapter 12 Operations AltitudeTM 4000 Series Access Point System Reference Guide 420...
Страница 520: ...Appendix A Customer Support AltitudeTM 4000 Series Access Point System Reference Guide 520...
Страница 521: ......