Download mGuard User Manual 7.4 - Innominate Security Technologies AG
Transcript
mGuard 7.4 Network Security >> Packet Filter >> Advanced (continued) Allow TCP keepalive packets without TCP flags TCP packets without set flags in their TCP header are normally rejected by firewalls. At least one type of Siemens control with older firmware sends TCP keepalive packets without set TCP flags, which are then rejected as invalid by the mGuard. The Yes setting allows the forwarding of TCP packets where no TCP flags are set in the header. This only applies when TCP packets of this type are sent within an existing TCP connection with a regular structure. TCP packets without TCP flags do not result in a new entry in the connection table (see “Connection Tracking” on page 6-149). If the connection is established when the mGuard is restarted, then corresponding packets are still rejected and connection problems are observed as long as no packets with flags belonging to the connection are sent. This setting applies to all TCP packets without flags. The Yes setting thus weakens the security functions provided by the mGuard. Network Modes (Router/PPTP/PPPoE) ICMP via primary external interface for the mGuard With this option you can control which ICMP messages from the external network are accepted by the mGuard via the primary / secondary external interface. ICMP via secondary external interface for the mGuard Regardless of this setting, incoming ICMP packets are always accepted if SNMP access is enabled. Drop: All ICMP messages directed to the mGuard are dropped. Allow ping requests: Only ping messages sent to the mGuard (ICMP type 8) are accepted. Allow all ICMPs: All ICMP messages to the mGuard are accepted. Stealth Mode Allow forwarding of GVRP frames Yes / No The GARP VLAN Registration Protocol (GVRP) is used by GVRP capable switches to exchange configuration information. When set to Yes, GVRP frames are allowed to pass through the mGuard in Stealth mode. Allow forwarding of STP frames Yes / No The Spanning Tree Protocol (STP) (802.1d) is used by bridges and switches to detect and consider loops in the network topology. When set to Yes, STP frames are allowed to pass through the mGuard in Stealth mode. 6-148 INNOMINATE 7961_en_04