18
©
SOLIDA SYSTEMS INTERNATIONAL 2017
6. Deep Packet Inspection Configuration
Deep packet inspection (DPI) refers to the process that inspects all incoming and outgoing
network packets. The factory default setting applies DPI on all packets, including incoming and
outgoing packets. Only under very special circumstances should the factory default be changed.
Changing the factory default will prohibit the appliance from detecting all possible malwares
and other threats.
To change the factory default setting, start the configuration utility and navigate to
“Configuration”. Locate the block titled “Deep Packet Inspection Configuration”. It will look as
shown in the picture below.
Figure 6.1 Deep packet inspection configuration window.
The following settings are available:
Packets from the Internet -
Inspect all packets (Factory default)
-
Disable Inspection
Packets from the LAN
-
Inspect all packets (Factory default)
-
Disable Inspection
Malformed Packets
-
Drop all malformed packets (Factory default)
-
Do not drop malformed packets
Hackers sometimes intentionally generate network packets that are malformed. The reason
might be to try and confuse, or even crash the system stacks in the computers connected to the
network. Letting the appliances drop these packets guarantees that they will not cause any
damage in the protected LAN.