Security Configuration 8 - 11
16. The firewall policy allows traffic filtering at the application layer using the
Application Layer Gateway
feature. The
Application Layer Gateway provides filters for the following common protocols:
17. Refer to the
Firewall Enhanced Logging
field to set the following parameters:
18. Select the
Enable Stateful DHCP Checks
radio button to enable the stateful checks of DHCP packet traffic through the
firewall. The default setting is enabled. When enabled, all DHCP traffic flows are inspected.
19. Define
Flow Timeout
intervals for the following flow types impacting the firewall:
Virtual Defragmentation
Timeout
Set the virtual defragmentation timeout to prevent IP fragment based attacks. Set a value
from 1 - 60 seconds. The default value is 1 second.
FTP ALG
Select the
Enable
box to allow FTP traffic through the firewall using its default ports. This
feature is enabled by default.
TFTP ALG
Select the
Enable
box to allow TFTP traffic through the firewall using its default ports. This
feature is enabled by default.
SIP ALG
Select the
Enable
box to allow SIP traffic through the firewall using its default ports. This
feature is enabled by default.
SCCP ALG
Select the check box to allow SCCP traffic through the firewall using its default ports. This
feature is enabled by default.
Signalling Connection Control Part
(SCCP) is a network
protocol that provides routing, flow control and error correction in telecommunication
networks.
FaceTime ALG
Select the check box to allow Apple’s FaceTime video calling traffic through the firewall
using its default port. This feature is enabled by default.
Log Dropped ICMP
Packets
Use the drop-down menu to define how dropped ICMP packets are logged. Logging can
be rate limited for one log instance every 20 seconds. Options include
Rate Limited
,
All
or
None
. The default setting is None.
Log Dropped Malformed
Packets
Use the drop-down menu to define how dropped malformed packets are logged. Logging
can be rate limited for one log instance every 20 seconds. Options include
Rate Limited
,
All
or
None
. The default setting is None.
Enable Verbose Logging
Select this option to enable verbose logging for dropped packets. This setting is disabled
by default.
TCP Close Wait
Define a flow timeout value in either
Seconds
(1 - 32,400),
Minutes
(1 - 540) or
Hours
(1 - 9). The default setting is 10 seconds.
TCP Established
Define a flow timeout value in either
Seconds
(15 - 32,400),
Minutes
(1 - 540) or
Hours
(1 - 9). The default setting is 90 minutes.
TCP Reset
Define a flow timeout value in either
Seconds
(1 - 32,400),
Minutes
(1 - 540) or
Hours
(1 - 9). The default setting is 10 seconds.
TCP Setup
Define a flow timeout value in either
Seconds
(1 - 32,400),
Minutes
(1 - 540) or
Hours
(1 - 9). The default setting is 10 seconds.
Содержание WiNG 5.6
Страница 1: ...Motorola Solutions WiNG 5 6 ACCESS POINT SYSTEM REFERENCE GUIDE ...
Страница 2: ......
Страница 3: ...MOTOROLA SOLUTIONS WING 5 6 ACCESS POINT SYSTEM REFERENCE GUIDE MN000335A01 Revision A March 2014 ...
Страница 22: ...8 WiNG 5 6 Access Point System Reference Guide ...
Страница 26: ...1 4 WiNG 5 6 Access Point System Reference Guide ...
Страница 38: ...2 12 WiNG 5 6 Access Point System Reference Guide ...
Страница 74: ...3 36 WiNG 5 6 Access Point System Reference Guide ...
Страница 468: ...6 2 WiNG 5 6 Access Point System Reference Guide Figure 6 1 Configuration Wireless menu ...
Страница 568: ...6 102 WiNG 5 6 Access Point System Reference Guide ...
Страница 614: ...7 46 WiNG 5 6 Access Point System Reference Guide ...
Страница 660: ...8 46 WiNG 5 6 Access Point System Reference Guide ...
Страница 664: ...9 4 WiNG 5 6 Access Point System Reference Guide Figure 9 2 Captive Portal Policy screen Basic Configuration tab ...
Страница 716: ...9 56 WiNG 5 6 Access Point System Reference Guide ...
Страница 730: ...10 14 WiNG 5 6 Access Point System Reference Guide ...
Страница 776: ...12 36 WiNG 5 6 Access Point System Reference Guide Figure 12 46 Device Summary screen 4 Click File Management ...
Страница 792: ...12 52 WiNG 5 6 Access Point System Reference Guide Figure 12 60 Certificate Management Import New Trustpoint screen ...
Страница 982: ...14 20 WiNG 5 6 Access Point System Reference Guide ...
Страница 984: ...A 2 WiNG 5 6 Access Point System Reference Guide ...
Страница 1046: ...B 62 WiNG 5 6 Access Point System Reference Guide ...
Страница 1047: ......