18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 8: Creating Rules and Rule Groups<br />

Creating IP Filter rules<br />

3 In the Idle Timeout field, specify the amount <strong>of</strong> time (in seconds) that a<br />

session will remain open when there is no new traffic within an established<br />

session. Valid values are 1–65535. (The minimum value is one second.)<br />

4 [TCP only] In the Limit Connection Rate area, you can limit the number <strong>of</strong><br />

connections that will be allowed per second by selecting Yes, and entering<br />

the number <strong>of</strong> connections that you want allowed per second in the Rate<br />

field. Valid values are 0—1000000000.<br />

To disable connection rate limitations, select No.<br />

5 [UDP only] In the Limit Packet Rate area, you can limit the number <strong>of</strong><br />

packets that will be allowed per second in either direction by selecting Yes,<br />

and entering the number <strong>of</strong> packets that you want allowed per second in the<br />

Rate field. Valid values are 0—1000000000.<br />

To disable packet rate limitations, select No.<br />

6 [Conditional] In the Stateful Session Failover field, select Yes to enable<br />

stateful session sharing, or select No to disable stateful session sharing.<br />

This field can only be modified if you are connected to an HA cluster. (For<br />

more information on stateful session sharing, see “Sharing IP Filter<br />

sessions in an HA cluster” on page 128.)<br />

7 In the Allowed Control and Error Responses area, select the response<br />

types that you want to allow for this rule by selecting the check box next to<br />

each response type you want to allow. A check mark will appear next to<br />

response types that are selected. To deselect a response type, click the<br />

check box to clear it.<br />

Note: This section controls the ICMP messages generated by this rule’s TCP/<br />

UDP traffic. These messages do not need separate ICMP rules.<br />

8 Click Add to save your changes, or click Cancel to reset the fields to the<br />

values that were previously entered.<br />

9 [Conditional] If you selected Add and want this rule to begin managing<br />

traffic, add this newly configured rule to an active rule group and save the<br />

changes.<br />

Your TCP/UDP IP Filter rule is now configured.<br />

Configuring the ICMP Advanced tab<br />

1 To enable stateful inspection for this rule, select the Stateful Packet<br />

Inspection check box. You will not be able to configure other fields in this<br />

tab without this option selected.<br />

To disable stateful packet inspection, clear the Stateful Packet Inspection<br />

check box.<br />

2 In the Response Timeout field, specify the amount <strong>of</strong> time (in seconds) that<br />

a session will await responses after the final request. The minimum value is<br />

1 second.<br />

235

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!