
Session Handling
44
Note that
drop
and
reject
both drop packets, with the difference only being whether notification of this
is sent back to the traffic source.
Tip
For a short period after startup the actions of
drop
and
reject
are treated as
ignore
. This is so
that a reboot which would forget all sessions allows sessions that have outbound traffic which is not
NAT stand a chance of re-establishing by use of outbound traffic. Without this delay, incoming traffic
would create a drop/reject short lived session and could send an icmp error closing the connection.
This is configurable per
rule-set
.
Note
It is possible to mis-understand the function of the
no-match-action
attribute, given where it is
specified (i.e. an attribute of the rule-set object). This is particularly true when using XML. If you are
unfamiliar with the FB6000's session rule specifications, you may interpret the
no-match-action
as specifying what happens if the rule-set's entry-criteria are not met (i.e. at the beginning of processing
a rule-set).
no-match-action
specifies what happens after the entry-criteria were met, and all the rules were
considered, but none of them matched ("no-match") i.e. at the very end of processing a rule-set.
Caution
If all rule-sets have been considered, and no action has specified that the session should be dropped
or rejected, it will be ALLOWED. The factory default rule-sets have a firewall rule with
no-match-
action
set to drop to avoid this happening by mistake.
We recommend you use the firewall diagnostic tests to verify that you have constructed rule-sets
and rules that provide the firewalling you intended. We also highly recommend external intrusion
testing to verify behaviour. We also recommend that firewalling is done using the method described
in Section 7.3.3.1.
This processing flow is illustrated as a flow-chart in Figure 7.2 :-
Содержание FB6402
Страница 1: ...FireBrick FB6402 User Manual FB6000 Versatile Network Appliance...
Страница 2: ......