![Motorola Solutions WiNG 5.2.6 Скачать руководство пользователя страница 373](http://html.mh-extra.com/html/motorola/solutions-wing-5-2-6/solutions-wing-5-2-6_reference-manual_247423373.webp)
Security Configuration 7 - 13
21.Refer to the
TCP Protocol Checks
field to set the following parameters:
22.Select
OK
to update the Firewall Policy Advanced Settings. Select
Reset
to revert to the last saved configuration. The
Firewall policy can be invoked at any point in the configuration process by selecting
Activate Firewall Policy
from
the upper, left-hand side, of the access point user interface.
7.1.2 Configuring IP Firewall Rules
Wireless Firewall
Access points use IP based Firewalls like
Access Control Lists
(ACLs) to filter/mark packets based on the IP address from
which they arrive, as opposed to filtering packets on Layer 2 ports.
IP based Firewall rules are specific to source and destination IP addresses and the unique rules and precedence orders
assigned. Both IP and non-IP traffic on the same Layer 2 interface can be filtered by applying an IP ACL.
To add or edit an IP based Firewall Rule policy:
1. Select
Configuration
>
Security
>
IP Firewall Rules
to display existing IP Firewall Rule policies.
Check TCP states
where a SYN packet
tears down the flow
Select the checkbox to allow a SYN packet to delete an old flow in
TCP_FIN_FIN_STATE and TCP_CLOSED_STATE and create a new flow. The
default setting is enabled.
Check unnecessary
resends of TCP
packets
Select the checkbox to enable the checking of unnecessary resends of TCP
packets. The default setting is enabled.
Check Sequence
Number in ICMP
Unreachable error
packets
Select the checkbox to enable sequence number checks in ICMP
unreachable error packets when an established TCP flow is aborted.The
default setting is enabled.
Check
Acknowledgment
Number in RST
packets
Select the checkbox to enable the checking of the acknowledgment
number in RST packets which aborts a TCP flow in the SYN state. The
default setting is enabled.
Check Sequence
Number in RST
packets
Select the checkbox to check the sequence number in RST packets which
abort an established TCP flow. The default setting is enabled.
NOTE:
Once defined, a set of IP Firewall rules must be applied to an interface to be a
functional filtering tool.
Содержание Solutions WiNG 5.2.6
Страница 1: ...Motorola Solutions WiNG 5 2 6 Access Point System Reference Guide ...
Страница 2: ......
Страница 14: ...1 4 WiNG 5 2 6 Access Point System Reference Guide ...
Страница 26: ...2 12 WiNG 5 2 6 Access Point System Reference Guide ...
Страница 46: ...3 20 WiNG 5 2 6 Access Point System Reference Guide ...
Страница 247: ...Device Configuration 5 189 Figure 5 102 Profile Overrides Management Settings screen ...
Страница 264: ...6 2 WiNG 5 2 6 Access Point System Reference Guide Figure 6 1 Configuration Wireless ...
Страница 392: ...7 32 WiNG 5 2 6 Access Point System Reference Guide ...
Страница 438: ...8 46 WiNG 5 6 2 Access Point System Reference Guide ...
Страница 514: ...12 12 WiNG 5 2 6 Access Point System Reference Guide Figure 12 6 RF Domain Health screen ...
Страница 533: ...Statistics 12 31 Figure 12 18 RF Domain Smart RF Energy Graph ...
Страница 597: ...Statistics 12 95 Figure 12 54 Access Point Certificate Trustpoint screen ...
Страница 626: ...12 124 WiNG 5 2 6 Access Point System Reference Guide ...
Страница 628: ...A 2 WiNG 5 2 6 Access Point System Reference Guide ...
Страница 669: ......