Advanced Configuration
Firebox Vclass User Guide
131
- To ignore a DF bit (Don’t Fragment) during an
IPSec transmission, select the
Ignore DF for
IPSec
checkbox.
- To allow IPSec traffic to pass through to an
internal address that is using NAT, select the
IPSec pass-through
checkbox.
ICMP Error Handling
Regular network traffic may include various ICMP
error messages. You can allow all of these messages
or select the specific messages.
- Select
Allow All ICMP Error Messages
or
Allow
Specified ICMP Error Messages
.
- If you selected to allow only specified ICMP error
messages, enable the error messages you want to
allow.
TCP Maximum Segment Size Adjustment
This feature works in conjunction with the MTU
settings to limit the size of packets, if configured.
This feature overcomes the following problems:
- Oversized packets can result in fragmentation,
degrading VPN performance.
- Proxies may require MSS adjustment to prevent
fragmentation.
- Some older systems do not support MTU to
regulate packet size. This feature works along
with MTU; it does not replace MTU.
The following settings are available:
Auto Adjustment
Auto adjustment calculates the MSS automatically,
using the following calculations:
- Determining the lesser value of the input port
MTU and the output port MTU.
- Subtracting packet overhead, including IP and
TCP addressing, VLAN, ESP, PPPoE, AH, and
UDP encapsulation.
Summary of Contents for Firebox V10
Page 1: ...WatchGuard Firebox Vclass User Guide Vcontroller 5 0 ...
Page 32: ...xxxii Vcontroller ...
Page 40: ...CHAPTER 1 Introduction 8 Vcontroller ...
Page 52: ...CHAPTER 2 Service and Support 20 Vcontroller ...
Page 70: ...CHAPTER 3 Getting Started 38 Vcontroller ...
Page 110: ...CHAPTER 4 Firebox Vclass Basics 78 Vcontroller ...
Page 190: ...CHAPTER 7 Using Account Manager 158 Vcontroller ...
Page 268: ...CHAPTER 9 Security Policy Examples 236 Vcontroller ...
Page 410: ...CHAPTER 14 Monitoring the Firebox Vclass 378 Vcontroller ...
Page 456: ...CHAPTER 18 Using the Diagnostics CLI Feature 424 Vcontroller ...