Avaya BCM 4.0 Networking Konfigurationsanleitung Seite 726

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 758
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 725
726 Appendix D Stateful Packet Filters
N0060606N0060606
IID: ICMP protocol session identifier
ISEQ: ICMP protocol session sequence number
Examples of Stateful Session Processing
Example 1: ICMP
Setup:
Default rule: Enabled – Block incoming except IP phones
Outbound rules: None
Inbound rules:
Disposition: Block, SA: 10.10.10.2/32, stateful is enabled
Assumptions: No stateful sessions present to start
Scenario:
Table 180 Stateful Session Creation
Protocol Tuple Timeout Notes
ICMP PT, SA, DA, IID,
ISEQ
5 secs The session is selectively created when the following
ICMP operations numbers are present the in ICMP
playload:
8: echo request
13: timestamp request
15: information request
17: address mask request
TCP PT, SA, DA, SP,
DP
Varies from 30 secs
to 2 hours based on
TCP state machine
Extensive checks are performed against the TCP state
machine after a matching stateful session is retrieved.
This ensures early aging of the session in all cases.
UDP PT, SA, DA, SP,
DP
5 mins The timeout is always 5 minutes except for IKE packets
(SP and DP is equal to 500) where the timeout is 8
hours.
UDP PT, SA, DA, SP,
DP
5 mins The timeout is always 5 minutes except for IKE packets
(SP and DP is equal to 500) where the timeout is 8
hours.
ESP, AH PT, SA, DA 8 hours
Other protocols PT, SA, DA 5 mins
Table 181 Example 1: ICMP (Sheet 1 of 2)
Direction IP Datagram Outcome
Outbound PT: ICMP, SA: 10.10.10.1, DA: 10.10.10.2
ICMP: type 8 (echo request), IID:100, ISEQ: 1
No stateful session [ICMP, 10.10.10.1, 10.10.10.2,
100, 1]] is found. No user rule is found so the
default rule is used. A stateful session is created
with a disposition to “pass”.
Seitenansicht 725
1 2 ... 721 722 723 724 725 726 727 728 729 730 731 ... 757 758

Kommentare zu diesen Handbüchern

Keine Kommentare