Download mGuard User Manual 7.4 - Innominate Security Technologies AG

Transcript
mGuard 7.4
Network Security >> Packet Filter >> Advanced (continued)
Allow TCP keepalive
packets without
TCP flags
TCP packets without set flags in their TCP header are
normally rejected by firewalls. At least one type of Siemens
control with older firmware sends TCP keepalive packets
without set TCP flags, which are then rejected as invalid by
the mGuard.
The Yes setting allows the forwarding of TCP packets where
no TCP flags are set in the header. This only applies when
TCP packets of this type are sent within an existing TCP
connection with a regular structure.
TCP packets without TCP flags do not result in a new entry
in the connection table (see “Connection Tracking” on
page 6-149). If the connection is established when the
mGuard is restarted, then corresponding packets are still
rejected and connection problems are observed as long as
no packets with flags belonging to the connection are sent.
This setting applies to all TCP packets without flags. The
Yes setting thus weakens the security functions provided by
the mGuard.
Network Modes
(Router/PPTP/PPPoE)
ICMP via primary
external interface for
the mGuard
With this option you can control which ICMP messages from
the external network are accepted by the mGuard via the
primary / secondary external interface.
ICMP via secondary
external interface for
the mGuard
Regardless of this setting, incoming ICMP
packets are always accepted if SNMP access
is enabled.
Drop: All ICMP messages directed to the mGuard
are dropped.
Allow ping requests: Only ping messages sent to the
mGuard (ICMP type 8) are accepted.
Allow all ICMPs: All ICMP messages to the mGuard
are accepted.
Stealth Mode
Allow forwarding of
GVRP frames
Yes / No
The GARP VLAN Registration Protocol (GVRP) is used
by GVRP capable switches to exchange configuration
information.
When set to Yes, GVRP frames are allowed to pass through
the mGuard in Stealth mode.
Allow forwarding of
STP frames
Yes / No
The Spanning Tree Protocol (STP) (802.1d) is used by
bridges and switches to detect and consider loops in the
network topology.
When set to Yes, STP frames are allowed to pass through the
mGuard in Stealth mode.
6-148
INNOMINATE
7961_en_04