threshold is exceeded, the packet is dropped. A new session can be created only when
the session counts drop below the threshold when existing sessions are aged out.
Configuring the Session Close Notification Rule
An idle TCP connection remains established until terminated by either the client or the
server. If, for any reason, the client or an intermediate device shuts down, the server
continues to wait on the connection. As an intermediate security device, a device running
ScreenOS maintains a session for each TCP connection until it times out. Traffic can
resume if a client sends an RST (reset) packet, but the client needs to be informed of
the situation in order to do so. If the TCP keep-alive option is activated on the server, it
can be used to query the status of the connection.
NSM offers the option of configuring the SSG Series Secure Services Gateways, ISG
Series Integrated Security Gateways, and the NetScreen Series Security Systems running
ScreenOS 6.3 and later to send a notification to both the client and the server when a
TCP session is closed. By default, this option is disabled. Before you can enable the
Session Close Notification feature on NSM for a device, you must first set the following
options:
a. From
Device
>
Advanced
>
Packet flow
>:
•
Disable
Skip TCP sequence number check.
•
Enable one or both of these options:
•
Check TCP SYN bit before create/refresh session after TCP handshake
•
Check TCP SYN bit before Create session
•
Set the number of seconds in the option
Notify threshold.
b. From
Device
>
Network
>
Edit the From / To Zone
, enable
TCP/RST
.
Configuring the Session Close Notification option:
1.
Select
Policy Manager
>
Security Policy
>
Policy on device
>
Rule Options
>
Session Close
Notification
. A
Session Close Notification
window opens.
2.
Check the option –
Notify both ends if TCP session isn’t normally terminated
.
3.
Click
OK
.
configure the Session Close Notification option by selecting
Policy Manager
>
Security
Policy
>
Policy on device
>
Rule Options
>
Configure All Options Session Close Notification
.
Comments for Firewall Rules
The Comments column of a rule contains the rule title, which is also the ScreenOS policy
name (the name of the policy when viewing the device configuration using the WebUI).
You can also enter comments in the Comment Field, if desired.
465
Copyright © 2010, Juniper Networks, Inc.
Chapter 9: Configuring Security Policies
Содержание NETWORK AND SECURITY MANAGER 2010.4 - ADMININISTRATION GUIDE REV1
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Страница 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Страница 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Страница 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Страница 236: ...Copyright 2010 Juniper Networks Inc 186 Network and Security Manager Administration Guide...
Страница 292: ...Copyright 2010 Juniper Networks Inc 242 Network and Security Manager Administration Guide...
Страница 314: ...Copyright 2010 Juniper Networks Inc 264 Network and Security Manager Administration Guide...
Страница 368: ...Copyright 2010 Juniper Networks Inc 318 Network and Security Manager Administration Guide...
Страница 370: ...Copyright 2010 Juniper Networks Inc 320 Network and Security Manager Administration Guide...
Страница 484: ...Copyright 2010 Juniper Networks Inc 434 Network and Security Manager Administration Guide...
Страница 584: ...Copyright 2010 Juniper Networks Inc 534 Network and Security Manager Administration Guide...
Страница 588: ...Copyright 2010 Juniper Networks Inc 538 Network and Security Manager Administration Guide...
Страница 600: ...Copyright 2010 Juniper Networks Inc 550 Network and Security Manager Administration Guide...
Страница 678: ...Copyright 2010 Juniper Networks Inc 628 Network and Security Manager Administration Guide...
Страница 694: ...Copyright 2010 Juniper Networks Inc 644 Network and Security Manager Administration Guide...
Страница 700: ...Copyright 2010 Juniper Networks Inc 650 Network and Security Manager Administration Guide...
Страница 706: ...Copyright 2010 Juniper Networks Inc 656 Network and Security Manager Administration Guide...
Страница 708: ...Copyright 2010 Juniper Networks Inc 658 Network and Security Manager Administration Guide...
Страница 758: ...Copyright 2010 Juniper Networks Inc 708 Network and Security Manager Administration Guide...
Страница 788: ...Copyright 2010 Juniper Networks Inc 738 Network and Security Manager Administration Guide...
Страница 882: ...Copyright 2010 Juniper Networks Inc 832 Network and Security Manager Administration Guide...
Страница 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Страница 918: ...Copyright 2010 Juniper Networks Inc 868 Network and Security Manager Administration Guide...
Страница 920: ...Copyright 2010 Juniper Networks Inc 870 Network and Security Manager Administration Guide...
Страница 1005: ...PART 6 Index Index on page 957 955 Copyright 2010 Juniper Networks Inc...
Страница 1006: ...Copyright 2010 Juniper Networks Inc 956 Network and Security Manager Administration Guide...