DefensePro User Guide
Security Configuration
136
Document ID: RDWR-DP-V0602_UG1201
Action
The action that the device takes when the packet anomaly is detected.
The action is only for the specified anomaly.
Values:
•
Drop—The device discards the anomalous packets.
•
Report—If the device cannot handle the anomaly type, the packet
bypasses the rest of the device modules, and the device issues a
trap. If the device can handle the anomaly type, the packet goes
to the rest of the device modules, and the device issues a trap.
•
No Report—If the device cannot handle the anomaly type, the
packet bypasses the rest of the device modules. If the device can
handle the anomaly type, the packet goes to the rest of the device
modules.
Note:
Click Drop All to set the action for all anomaly types to Drop.
Click Report All to set the action for all anomaly types to
Report. Click No Report All to set the action for all anomaly
types to No Report.
Risk
The risk associated with the trap for the specific anomaly.
Values: Info, Low, Medium, High
Default: Info.
Table 68: Default Configuration of Packet Anomaly Types
Anomaly Type
Description
Unrecognized L2 Format
1
Packets with more than two VLAN tags or MPLS labels, L2 broadcast,
or L2 multicast traffic.
ID: 100
Default Action: No Report
Default Risk: Info
Incorrect IPv4 Checksum
1
The IP packet header checksum does not match the packet header.
ID: 103
Default Action: Drop
Default Risk: Info
Invalid IPv4 Header or
Total Length
The IP packet header length does not match the actual header length,
or the IP packet total length does not match the actual packet length.
ID: 104
Default Action: Drop
Default Risk: Info
Note:
All DefensePro platforms support this anomaly type.
TTL Less Than or Equal to
1
1
The TTL field value is less than or equal to 1.
ID: 105
Default Action: Report
Default Risk: Info
Table 67: Packet Anomaly Protection Parameters
Parameter
Description
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...