D-Link DFL-260E CLI Guide for DFL-260E - Page 189

TCP NULL packets without SYN, ACK, FIN or

Page 189 highlights

3.52.23. VLANSettings Chapter 3. Configuration Reference TCPSynFin TCPFinUrg TCPUrg TCPECN TCPRF TCPNULL TCPSequenceNumbers TCPAllowReopen valid (strip=strip RST). (Default: DropLog) The TCP FIN flag together with SYN; normally invalid (strip=strip FIN). (Default: DropLog) The TCP URG flag together with FIN; normally invalid (strip=strip URG). (Default: DropLog) The TCP URG flag; many operating systems cannot handle this correctly. (Default: StripLog) The Explicit Congestion Notification (ECN) flags. Previously known as "XMAS"/"YMAS" flags. Also used in OS fingerprinting. (Default: StripLog) The TCP Reserved field: should be zero. Used in OS fingerprinting. Also part of ECN extension. (Default: StripLog) TCP "NULL" packets without SYN, ACK, FIN or RST; normally invalid, used by scanners. (Default: DropLog) Validation of TCP sequence numbers. (Default: ValidateLogBad) Allow clients to re-open TCP connections that are in the closed state. (Default: No) Note This object type does not have an identifier and is identified by the name of the type only. There can only be one instance of this type. 3.52.23. VLANSettings Description Settings for IEEE 802.1Q based Virtual LAN interfaces. Properties UnknownVLANTags VLAN packets tagged with an unknown ID. (Default: DropLog) Note This object type does not have an identifier and is identified by the name of the type only. There can only be one instance of this type. 189

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198

valid (strip=strip RST). (Default: DropLog)
TCPSynFin
The TCP FIN flag together with SYN; normally in-
valid (strip=strip FIN). (Default: DropLog)
TCPFinUrg
The TCP URG flag together with FIN; normally in-
valid (strip=strip URG). (Default: DropLog)
TCPUrg
The TCP URG flag; many operating systems cannot
handle this correctly. (Default: StripLog)
TCPECN
The Explicit Congestion Notification (ECN) flags.
Previously known as "XMAS"/"YMAS" flags. Also
used in OS fingerprinting. (Default: StripLog)
TCPRF
The TCP Reserved field: should be zero. Used in OS
fingerprinting. Also part of ECN extension. (Default:
StripLog)
TCPNULL
TCP "NULL" packets without SYN, ACK, FIN or
RST; normally invalid, used by scanners. (Default:
DropLog)
TCPSequenceNumbers
Validation of TCP sequence numbers. (Default: Val-
idateLogBad)
TCPAllowReopen
Allow clients to re-open TCP connections that are in
the closed state. (Default: No)
Note
This object type does not have an identifier and is identified by the name of the type
only. There can only be one instance of this type.
3.52.23. VLANSettings
Description
Settings for IEEE 802.1Q based Virtual LAN interfaces.
Properties
UnknownVLANTags
VLAN
packets
tagged
with
an
unknown
ID.
(Default: DropLog)
Note
This object type does not have an identifier and is identified by the name of the type
only. There can only be one instance of this type.
3.52.23. VLANSettings
Chapter 3. Configuration Reference
189