Default:
7000 bytes
TCP Auto Clamping
Automatically clamp TCP MSS according to MTU of involved interfaces, in addition to
TCPMSSMax.
Default:
Enabled
TCP Zero Unused ACK
Determines whether NetDefendOS should set the ACK sequence number field in TCP packets to
zero if it is not used. Some operating systems reveal sequence number information this way,
which can make it easier for intruders wanting to hijack established connections.
Default:
Enabled
TCP Zero Unused URG
Strips the URG pointers from all packets.
Default:
Enabled
TCP Option WSOPT
Determines how NetDefendOS will handle window-scaling options. These are used to increase
the size of the window used by TCP; that is to say, the amount of information that can be sent
before the sender expects ACK. They are also used by OS Fingerprinting. WSOPT is a common
occurrence in modern networks.
Default:
ValidateLogBad
TCP Option SACK
Determines how NetDefendOS will handle selective acknowledgment options. These options are
used to ACK individual packets instead of entire series, which can increase the performance of
connections experiencing extensive packet loss. They are also used by OS Fingerprinting. SACK is
a common occurrence in modern networks.
Default:
ValidateLogBad
TCP Option TSOPT
Determines how NetDefendOS will handle time stamp options. As stipulated by the PAWS
(Protect Against Wrapped Sequence numbers) method, TSOPT is used to prevent the sequence
numbers (a 32-bit figure) from "exceeding" their upper limit without the recipient being aware of
it.
This is not normally a problem. Using TSOPT, some TCP stacks optimize their connection by
measuring the time it takes for a packet to travel to and from its destination. This information can
then be used to generate resends faster than is usually the case. It is also used by OS
Fingerprinting. TSOPT is a common occurrence in modern networks.
Default:
ValidateLogBad
Chapter 13: Advanced Settings
854
Summary of Contents for NetDefendOS
Page 30: ...Figure 1 3 Packet Flow Schematic Part III Chapter 1 NetDefendOS Overview 30 ...
Page 32: ...Chapter 1 NetDefendOS Overview 32 ...
Page 144: ...Chapter 2 Management and Maintenance 144 ...
Page 284: ...Chapter 3 Fundamentals 284 ...
Page 392: ...Chapter 4 Routing 392 ...
Page 419: ... Host 2001 DB8 1 MAC 00 90 12 13 14 15 5 Click OK Chapter 5 DHCP Services 419 ...
Page 420: ...Chapter 5 DHCP Services 420 ...
Page 573: ...Chapter 6 Security Mechanisms 573 ...
Page 607: ...Chapter 7 Address Translation 607 ...
Page 666: ...Chapter 8 User Authentication 666 ...
Page 775: ...Chapter 9 VPN 775 ...
Page 819: ...Chapter 10 Traffic Management 819 ...
Page 842: ...Chapter 11 High Availability 842 ...
Page 866: ...Default Enabled Chapter 13 Advanced Settings 866 ...
Page 879: ...Chapter 13 Advanced Settings 879 ...