05.08.2013 Views

Intrusion Defense Firewall 1.2 User's Guide - Trend Micro? Online ...

Intrusion Defense Firewall 1.2 User's Guide - Trend Micro? Online ...

Intrusion Defense Firewall 1.2 User's Guide - Trend Micro? Online ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The ICMP (pseudo-)stateful mechanism drops incoming unsolicited ICMP packets. For every<br />

outgoing ICMP packet, the rule will create or update its ICMP "stateful" table and will then only allow a<br />

ICMP response if it occurs within 60 seconds of the request. (ICMP pair types supported: Type 0 & 8,<br />

13 & 14, 15 & 16, 17 & 18. )<br />

With stateful ICMP inspection enabled, you can, for example, only allow an ICMP echo-reply in if an<br />

echo-request has been sent out. Unrequested echo-replies could be a sign of several kinds of attack<br />

including a Smurf amplification attack, a Tribe Flood Network communication between master and<br />

daemon, or a Loki 2 back-door.<br />

Assigned To<br />

o Enable ICMP stateful logging: Checking this option will enable the logging of ICMP<br />

stateful inspection events.<br />

The Assigned To tab lists the Security Profiles and Computers that are making use of this stateful<br />

inspection configuration.<br />

© Copyright 2010 <strong>Trend</strong> <strong>Micro</strong> Inc. www.trendmicro.com<br />

All rights reserved. - 37 -

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!