18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Modifying the<br />

interface<br />

configuration<br />

Chapter 3: General System Tasks<br />

Modifying the interface configuration<br />

2 The following settings may be enabled or disabled for each burb:<br />

• Hide port unreachables—If this parameter is enabled, the <strong>Sidewinder</strong><br />

<strong>G2</strong> will give no response if a node on the network attempts to connect to<br />

a port on which the <strong>Sidewinder</strong> <strong>G2</strong> is not listening. This increases<br />

security by not divulging configuration information to potential hackers.<br />

• Intra-burb packet forwarding—If enabled, traffic will be forwarded<br />

between network interfaces located within this burb. Disabling this<br />

parameter in a burb with two or more network interfaces has the effect<br />

<strong>of</strong> separating the interfaces. This parameter should be disabled in burbs<br />

with only one network interface.<br />

Note: There is an interaction between the Intra-burb packet forwarding<br />

parameter and NAT. NAT changes the source address <strong>of</strong> outbound packets<br />

to the IP address <strong>of</strong> the <strong>Sidewinder</strong> <strong>G2</strong> in the external (outgoing) burb. If<br />

multiple interfaces exist in the same burb, that <strong>Sidewinder</strong> <strong>G2</strong> has to select<br />

an appropriate address based upon how it routes packets. By enabling this<br />

option, the <strong>Sidewinder</strong> <strong>G2</strong> must choose one <strong>of</strong> the interfaces for the source<br />

address. In this case the <strong>Sidewinder</strong> <strong>G2</strong> will always choose the address <strong>of</strong><br />

the first interface in the burb. Problems could occur if the destination is not<br />

defined to use the same route back to the <strong>Sidewinder</strong> <strong>G2</strong>.<br />

• Honor ICMP redirects—ICMP messages are used to optimize the<br />

routes for getting IP traffic to the proper destination. On a trusted<br />

network, honoring ICMP redirects can improve the throughput <strong>of</strong> the<br />

system. On an untrusted network, ICMP redirects can be used by<br />

hackers to examine, reroute, or steal network traffic. Enabling this<br />

parameter allows the <strong>Sidewinder</strong> <strong>G2</strong> to honor ICMP redirects.<br />

• Respond to ICMP echo and timestamp—ICMP echo and timestamp<br />

messages (also known as ping messages) are used to test addresses<br />

on a network. The messages are a handy diagnostic tool, but can also<br />

be used by hackers to probe for weaknesses. Enabling this parameter<br />

allows the <strong>Sidewinder</strong> <strong>G2</strong> to respond to these messages.<br />

3 In the Internet burb drop-down list, specify which <strong>of</strong> the burbs defined on<br />

the <strong>Sidewinder</strong> <strong>G2</strong> is the Internet burb. The Internet burb is unique because<br />

it is the only burb that communicates directly with the outside world.<br />

4 Click the Save icon to save your changes.<br />

The installation process defines <strong>Sidewinder</strong> <strong>G2</strong>’s internal and external network<br />

interfaces. You can configure up to 64 interfaces, using a combination <strong>of</strong><br />

physical and VLAN interfaces. Using the Admin Console you can configure the<br />

media type, the IP address, the subnet mask associated with an interface, and<br />

the burb assigned to an interface. You can also enable hardware acceleration,<br />

VLANs, DHCP, support for jumbo frames, and TCP checksum <strong>of</strong>floading.<br />

To modify your interface configuration, start the Admin Console and select<br />

Firewall <strong>Administration</strong> > Interface Configuration. The following window<br />

appears.<br />

83

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!