Figure 6.1. Deploying an ALG
ALGs Are Not State Synchronized
No aspect of ALGs are state synchronized in a NetDefendOS high availability cluster.
This means that all traffic handled by ALGs will freeze when a cluster fails over to the
other peer. However, if the cluster fails back over to the original peer within
approximately half a minute, frozen sessions and their associated transfers) should
begin working again. Note that such a failover with almost immediate fallback occurs
each time a new configuration is uploaded.
Maximum Connection Sessions
The service associated with an ALG has a configurable parameter associated with it called
Max
Sessions
and the default value varies according to the type of ALG. For instance, the default value
for the HTTP ALG is
1000
. This means that a 1000 connections are allowed in total for the HTTP
service across all interfaces. The full list of default maximum session values are:
•
HTTP ALG -
1000
sessions.
•
FTP ALG -
200
sessions.
•
TFTP ALG -
200
sessions.
•
SMTP ALG -
200
sessions.
•
POP3 ALG -
200
sessions.
•
H.323 ALG -
100
sessions.
•
SIP ALG -
200
sessions.
Tip: Maximum sessions for HTTP can sometimes be too low
This default value of the maximum sessions can often be too low for HTTP if there are
Chapter 6: Security Mechanisms
426
Summary of Contents for NetDefendOS
Page 30: ...Figure 1 3 Packet Flow Schematic Part III Chapter 1 NetDefendOS Overview 30 ...
Page 32: ...Chapter 1 NetDefendOS Overview 32 ...
Page 144: ...Chapter 2 Management and Maintenance 144 ...
Page 284: ...Chapter 3 Fundamentals 284 ...
Page 392: ...Chapter 4 Routing 392 ...
Page 419: ... Host 2001 DB8 1 MAC 00 90 12 13 14 15 5 Click OK Chapter 5 DHCP Services 419 ...
Page 420: ...Chapter 5 DHCP Services 420 ...
Page 573: ...Chapter 6 Security Mechanisms 573 ...
Page 607: ...Chapter 7 Address Translation 607 ...
Page 666: ...Chapter 8 User Authentication 666 ...
Page 775: ...Chapter 9 VPN 775 ...
Page 819: ...Chapter 10 Traffic Management 819 ...
Page 842: ...Chapter 11 High Availability 842 ...
Page 866: ...Default Enabled Chapter 13 Advanced Settings 866 ...
Page 879: ...Chapter 13 Advanced Settings 879 ...