Security Configuration 8 - 11
16. The firewall policy allows traffic filtering at the application layer using the
Application Layer Gateway
feature. The
Application Layer Gateway provides filters for the following common protocols:
17. Refer to the
Firewall Enhanced Logging
field to set the following parameters:
18. Select the
Enable Stateful DHCP Checks
radio button to enable the stateful checks of DHCP packet traffic through the
firewall. The default setting is enabled. When enabled, all DHCP traffic flows are inspected.
19. Define
Flow Timeout
intervals for the following flow types impacting the firewall:
Virtual Defragmentation
Timeout
Set the virtual defragmentation timeout to prevent IP fragment based attacks. Set a value
from 1 - 60 seconds. The default value is 1 second.
FTP ALG
Select the
Enable
box to allow FTP traffic through the firewall using its default ports. This
feature is enabled by default.
TFTP ALG
Select the
Enable
box to allow TFTP traffic through the firewall using its default ports. This
feature is enabled by default.
SIP ALG
Select the
Enable
box to allow SIP traffic through the firewall using its default ports. This
feature is enabled by default.
SCCP ALG
Select the check box to allow SCCP traffic through the firewall using its default ports. This
feature is enabled by default.
Signalling Connection Control Part
(SCCP) is a network
protocol that provides routing, flow control and error correction in telecommunication
networks.
FaceTime ALG
Select the check box to allow Apple’s FaceTime video calling traffic through the firewall
using its default port. This feature is enabled by default.
Log Dropped ICMP
Packets
Use the drop-down menu to define how dropped ICMP packets are logged. Logging can
be rate limited for one log instance every 20 seconds. Options include
Rate Limited
,
All
or
None
. The default setting is None.
Log Dropped Malformed
Packets
Use the drop-down menu to define how dropped malformed packets are logged. Logging
can be rate limited for one log instance every 20 seconds. Options include
Rate Limited
,
All
or
None
. The default setting is None.
Enable Verbose Logging
Select this option to enable verbose logging for dropped packets. This setting is disabled
by default.
TCP Close Wait
Define a flow timeout value in either
Seconds
(1 - 32,400),
Minutes
(1 - 540) or
Hours
(1 - 9). The default setting is 10 seconds.
TCP Established
Define a flow timeout value in either
Seconds
(15 - 32,400),
Minutes
(1 - 540) or
Hours
(1 - 9). The default setting is 90 minutes.
TCP Reset
Define a flow timeout value in either
Seconds
(1 - 32,400),
Minutes
(1 - 540) or
Hours
(1 - 9). The default setting is 10 seconds.
TCP Setup
Define a flow timeout value in either
Seconds
(1 - 32,400),
Minutes
(1 - 540) or
Hours
(1 - 9). The default setting is 10 seconds.
Summary of Contents for WiNG 5.6
Page 1: ...Motorola Solutions WiNG 5 6 ACCESS POINT SYSTEM REFERENCE GUIDE ...
Page 2: ......
Page 22: ...8 WiNG 5 6 Access Point System Reference Guide ...
Page 26: ...1 4 WiNG 5 6 Access Point System Reference Guide ...
Page 38: ...2 12 WiNG 5 6 Access Point System Reference Guide ...
Page 74: ...3 36 WiNG 5 6 Access Point System Reference Guide ...
Page 468: ...6 2 WiNG 5 6 Access Point System Reference Guide Figure 6 1 Configuration Wireless menu ...
Page 568: ...6 102 WiNG 5 6 Access Point System Reference Guide ...
Page 614: ...7 46 WiNG 5 6 Access Point System Reference Guide ...
Page 660: ...8 46 WiNG 5 6 Access Point System Reference Guide ...
Page 716: ...9 56 WiNG 5 6 Access Point System Reference Guide ...
Page 730: ...10 14 WiNG 5 6 Access Point System Reference Guide ...
Page 982: ...14 20 WiNG 5 6 Access Point System Reference Guide ...
Page 984: ...A 2 WiNG 5 6 Access Point System Reference Guide ...
Page 1046: ...B 62 WiNG 5 6 Access Point System Reference Guide ...
Page 1047: ......