Administrator’s Handbook
196
Stateful Inspection
Stateful inspection options are accessed by the
security state-insp
tag.
set security state-insp [ ip-ppp | dsl ] vcc
n
option [ off | on ]
set security state-insp ethernet [ A | B ] option [ off | on ]
Sets the stateful inspection option
off
or
on
on the specified inter face. This option is disabled by
default. Stateful inspection prevents unsolicited inbound access when NAT is disabled.
set security state-insp [ ip-ppp | dsl ] vcc
n
default-mapping [ off | on ]
set security state-insp ethernet [ A | B ] default-mapping [ off | on ]
Sets stateful inspection default mapping to Gateway option
off
or
on
on the specified inter face.
set security state-insp [ ip-ppp | dsl ] vcc
n
tcp-seq-diff [ 0 - 65535 ]
set security state-insp ethernet [ A | B ] tcp-seq-diff [ 0 - 65535 ]
Sets the acceptable TCP sequence difference on the specified inter face. The TCP sequence number dif-
ference maximum allowed value is 65535. If the value of
tcp-seq-diff
is 0, it means that this check is
disabled.
set security state-insp [ ip-ppp | dsl ] vcc
n
deny-fragments [ off | on ]
set security state-insp ethernet [ A | B ] deny-fragments [ off | on ]
Sets whether fragmented packets are allowed to be received or not on the specified inter face.
set security state-insp tcp-timeout [ 30 - 65535 ]
Sets the stateful inspection TCP timeout inter val, in seconds.
set security state-insp udp-timeout [ 30 - 65535 ]
Sets the stateful inspection UDP timeout inter val, in seconds.
set security state-insp dos-detect [ off | on ]
Enables or disables the stateful inspection Denial of Ser vice detection feature. If set to
on
, the device
will monitor packets for Denial of Ser vice (DoS) attack. Offending packets may be discarded if it is
determined to be a DoS attack.
set security state-insp xposed-addr exposed-address# "
n
"
Allows you to add an entr y to the specified list, or, if the list does not exist, creates the list for the
stateful inspection feature.
xposed-addr
settings only apply if NAT is off.
Example:
set security state-insp xposed-addr exposed-address# (?): 32
32 has been added to the
xposed-addr
list.
Содержание Netopia 3300
Страница 238: ...Administrator s Handbook 238 ...
Страница 254: ...Administrator s Handbook 254 Z Zero Touch 205 ...