12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Monitoring security gateway trafficAdvanced options109Advanced optionsOccasionally, the default state of the security gateway must be fine-tuned to run at peak performance. Thisfine-tuning is accomplished through parameters whose values can change. These variables are onlymodified under specific circumstances.Warning: Before modifying any security gateway advanced option, you should first contact SymantecTechnical Support to determine if the change is necessary.Table 8-3 lists security gateway modifiable parameters.Table 8-3Advanced optionsParameterantivirus.inf.content_blocked_noticeantivirus.liveupdate.protocolantivirus.liveupdate.workdircluster.dbglevelcluster.fotimeoutcluster.hashlbcluster.hbtimeoutcluster.lprotectcluster.lprotectpcntcluster.symroutecluster.useportcluster.viplbcontentfilter.liveupdate.protocolDescriptionDefinable message to send when a virus is detected and blocked. Thedefault is, “The message being sent to you had a virus and was blockedby Symantec’s AntiVirus Scan Engine.”Network protocol used by LiveUpdate when retrieving antivirusupdates. The default is HTTP.Working directory for the LiveUpdate engine when processing antivirusupdates. This defaults to /Symantec/LiveUpdate.Level of debug messages for HA/LB. The default value is 1 and can rangefrom 1 (minimal) to 5 (verbose).Time in seconds to wait before creating a failover record for aconnection. Failover records are costly, so setting this value below 30seconds has no affect. The default is 60 seconds. If this parameter is setto any value less than 30, that value is ignored, and 30 seconds is usedinstead.Determines whether or not the cluster uses the hash algorithm to directpackets. The default value is 0 (off). Acceptable values for thisparameter are 1 (on) and 0 (off).Time in seconds that nodes wait before pinging each other to ensureother nodes are reachable. The default value is 4 seconds. Acceptablevalues include any number of seconds, but the value chosen should bereasonable.Enables and disables load protection. When load protection is on,strained nodes drop random packets to alleviate load. The default valueis 0 (off). Acceptable values for this parameter are 1 (on) and 0 (off).Percentage of random packets to drop if cluster.lprotect is set to 1 (on).The default value is 7. Acceptable values include any positive integerbetween 1 and 100 inclusive.Symmetric routing. The default is 1 (on). Acceptable values for thisparameter are 1 (on) and 0 (off).Use 5-tuple (source, source port, destination, destination port, protocol)as one session. The default is 1 (on). Acceptable values for thisparameter are 1 (on) and 0 (off).Load balancing for the VIP incident node assignment. The default valueis 0 (off). Acceptable values for this parameter are 1 (on) and 0 (off).Network protocol used by LiveUpdate when retrieving content filteringupdates. The default is HTTP.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!