(Default: No)
Note
This object type does not have an identifier and is identified by the name of the type
only. There can only be one instance of this type.
3.55.11. IPSettings
Description
Settings related to the IP protocol.
Properties
LogCheckSumErrors
Log IP packets with bad checksums. (Default: Yes)
LogNonIP4
Log occurrences of non-IPv4 packets. (Default: Yes)
LogReceivedTTL0
Log received packets with TTL=0; this should never happen!
(Default: Yes)
Log0000Src
Log invalid 0.0.0.0 source address. (Default: Drop)
Block0Net
Block 0.* source addresses. (Default: DropLog)
Block127Net
Block 127.* source addresses. (Default: DropLog)
BlockMulticastSrc
Block
multicast
source
addresses
(224.0.0.0--255.255.255.255). (Default: DropLog)
TTLMin
The minimum IP Time-To-Live value accepted on receipt.
(Default: 3)
TTLOnLow
What action to take on too low unicast TTL values. (Default:
DropLog)
TTLMinMulticast
The minimum IP multicast Time-To-Live value accepted on
receipt. (Default: 3)
TTLOnLowMulticast
What action to take on too low multicast TTL values.
(Default: DropLog)
DefaultTTL
The default IP Time-To-Live of packets originated by the se-
curity gateway (32-255). (Default: 255)
LayerSizeConsistency
TCP/UDP/ICMP/etc layer data and header sizes matching
lower layer size information. (Default: ValidateLogBad)
SecuRemoteUDPEncapCompat
Allow IP data to contain eight bytes more than the UDP total
length field specifies -- Checkpoint SecuRemote violates
NAT-T drafts. (Default: No)
IPOptionSizes
Validity of IP header option sizes. (Default: ValidateLogBad)
IPOPT_SR
How to handle IP packets with contained source or return
routes. (Default: DropLog)
3.55.11. IPSettings
Chapter 3. Configuration Reference
193