12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Using Global SettingsEnable TOS for IPSecThe Type of Service (TOS) bits are a set of four-bit flags in the IP header that can tell routingdevices to give an IP datagram more or less priority than other datagrams. Fireware® gives youthe option to allow IPSec tunnels to pass T0S flagged packets. Some ISPs drop all packets thathave TOS flags set.If you do not select the Enable TOS for IPSec check box, all IPSec packets have no TOS bits set.If the TOS bits were set before, when Fireware encapsulates the packet in an IPSec header, theTOS bits are cleared.When the Enable TOS for IPSec check box is selected, if the original packet has TOS bits setthen Fireware keeps the TOS bits set when it encapsulates the packet in an IPSec header. If theoriginal packet does not have the TOS bits set, Fireware does not set the TOS bits when itencapsulates the packet in an IPSec header.ICMP error handlingInternet Control Message Protocol (ICMP) controls errors during connections. It is used for two types ofoperations:• To tell client hosts about error conditions.• To probe a network to find general characteristics about the network.The Firebox sends an ICMP error message each time an event occurs that matches one of the parametersyou selected. If you deny these ICMP messages, you can increase security by preventing networkprobes, but it can also cause time-out delays for incomplete connections and can cause applicationproblems. The global ICMP error handling parameters and their descriptions are:Fragmentation Req (PMTU)The IP datagram must be fragmented, but this is prevented because the Don’t Fragment bit inthe IP header is set.Time ExceededThe datagram was dropped because the Time to Live field expired.Network UnreachableThe datagram could not get to the network.Host UnreachableThe datagram could not get to the host.Port UnreachableThe datagram could not get to the port.Protocol UnreachableThe protocol piece of the datagram cannot be delivered.TCP SYN checkingThe global TCP SYN checking setting is:Enable TCP SYN checkingThis feature makes sure that the TCP three-way handshake is done before the Firebox allows a dataconnection.76 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!