SmartDefense Categories
290
Nokia IP60 Security Appliance User Guide
TCP
This category allows you to configure various protections related to the TCP protocol. It includes the
following:
Flags
on page 294
Sequence Verifier
on page 293
Small PMTU
on page 291
Strict TCP
on page 290
SynDefender
on page 292
Strict TCP
Out-of-state TCP packets are SYN-ACK or data packets that arrive out of order, before the TCP SYN
packet.
Note:
In normal conditions, out-of-state TCP packets can occur after the Nokia IP60
restarts, since connections which were established prior to the reboot are unknown.
This is normal and does not indicate an attack.
You can configure how out-of-state TCP packets should be handled.
Table 69: Strict TCP
In this field… Do this…
Action
Specify what action to take when an out-of-state TCP packet arrives, by
selecting one of the following:
Block.
Block the packets.
None.
No action. This is the default.
Track
Specify whether to log null payload ping packets, by selecting one of the
following:
Log.
Log the packets. This is the default.
None.
Do not log the packets.
Содержание IP60 - Security Appliance
Страница 1: ...Part No N450000643 Rev 001 Published February 2008 Nokia IP60 Security Appliance User Guide ...
Страница 4: ...4 Nokia IP60 Security Appliance User Guide ...
Страница 10: ......
Страница 12: ......
Страница 38: ......
Страница 58: ......
Страница 108: ......
Страница 268: ......
Страница 482: ......