CHAPTER 8: About Security Policies
210
Vcontroller
This feature works in conjunction with the MTU
settings, but on a per-policy basis, to limit the size of
packets, if configured. This feature overcomes the
following problems:
•
Oversized packets can result in fragmentation,
degrading VPN performance.
•
Proxies may require MSS adjustment to prevent
fragmentation.
•
Some older systems do not support MTU to regulate
packet size. This feature works along with MTU; it
does not replace MTU.
The following settings are available:
Auto Adjustment
Auto adjustment calculates the MSS automatically,
using the following calculations:
- Determining the lesser value of the input port
MTU and the output port MTU.
- Subtracting packet overhead, including IP and
TCP addressing, VLAN, ESP, PPPoE, AH, and
UDP encapsulation.
- The result is then rounded down to the next
lower multiple of 8 bits (8-bit aligned) to
determine the size in bytes that is required for
packet transmission.
The results of this calculation are used as the MSS
for the connection.
Limit to N Bytes (40-1460)
This limits MSS to the specified size in bytes.
No Adjustment
This specifies that no change be made to the TCP
header. In this case, fragmentation can happen.
7
When you have finished, click
Done
.
Summary of Contents for Firebox V10
Page 1: ...WatchGuard Firebox Vclass User Guide Vcontroller 5 0 ...
Page 32: ...xxxii Vcontroller ...
Page 40: ...CHAPTER 1 Introduction 8 Vcontroller ...
Page 52: ...CHAPTER 2 Service and Support 20 Vcontroller ...
Page 70: ...CHAPTER 3 Getting Started 38 Vcontroller ...
Page 110: ...CHAPTER 4 Firebox Vclass Basics 78 Vcontroller ...
Page 190: ...CHAPTER 7 Using Account Manager 158 Vcontroller ...
Page 268: ...CHAPTER 9 Security Policy Examples 236 Vcontroller ...
Page 410: ...CHAPTER 14 Monitoring the Firebox Vclass 378 Vcontroller ...
Page 456: ...CHAPTER 18 Using the Diagnostics CLI Feature 424 Vcontroller ...