18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Modifying the burb configuration<br />

2. The following settings may be enabled or disabled for each burb:<br />

Hide port unreachables—If this parameter is enabled, the<br />

<strong>Sidewinder</strong> <strong>G2</strong> will give no response if a node on the network<br />

attempts to connect to a port on which the <strong>Sidewinder</strong> <strong>G2</strong> is not<br />

listening. This increases security by not divulging configuration<br />

information to potential hackers.<br />

Intra-burb packet forwarding—If enabled, traffic will be forwarded<br />

between network interfaces located within this burb. Disabling<br />

this parameter in a burb with two or more network interfaces has<br />

the effect <strong>of</strong> separating the interfaces. This parameter should be<br />

disabled in burbs with only one network interface.<br />

Note: There is an interaction between the Intra-burb packet forwarding<br />

parameter and NAT. NAT changes the source address <strong>of</strong> outbound packets to<br />

the IP address <strong>of</strong> the <strong>Sidewinder</strong> <strong>G2</strong> in the external (outgoing) burb. If multiple<br />

interfaces exist in the same burb, that <strong>Sidewinder</strong> <strong>G2</strong> has to select an<br />

appropriate address based upon how it routes packets. By enabling this option,<br />

the <strong>Sidewinder</strong> <strong>G2</strong> must choose one <strong>of</strong> the interfaces for the source address. In<br />

this case the <strong>Sidewinder</strong> <strong>G2</strong> will always choose the address <strong>of</strong> the first interface<br />

in the burb. Problems could occur if the destination is not defined to use the<br />

same route back to the <strong>Sidewinder</strong> <strong>G2</strong>.<br />

Honor ICMP redirects—ICMP messages are used to optimize the<br />

routes for getting IP traffic to the proper destination. On a trusted<br />

network, honoring ICMP redirects can improve the throughput <strong>of</strong><br />

the system. On an untrusted network, ICMP redirects can be used<br />

by hackers to examine, reroute, or steal network traffic. Enabling<br />

this parameter allows the <strong>Sidewinder</strong> <strong>G2</strong> to honor ICMP redirects.<br />

Respond to ICMP echo and timestamp—ICMP echo and timestamp<br />

messages (also known as ping messages) are used to test<br />

addresses on a network. The messages are a handy diagnostic tool,<br />

but can also be used by hackers to probe for weaknesses. Enabling<br />

this parameter allows the <strong>Sidewinder</strong> <strong>G2</strong> to respond to these<br />

messages.<br />

3. In the Internet burb drop-down list, specify which <strong>of</strong> the burbs defined<br />

on the <strong>Sidewinder</strong> <strong>G2</strong> is the Internet burb. The Internet burb is unique<br />

because it is the only burb that communicates directly with the outside<br />

world.<br />

4. Click the Save icon to save your changes.<br />

General System Tasks 3-49

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!