D-Link DFL-860E CLI Guide for DFL-260E - Page 187

StateSettings, 52.22. TCPSettings

Page 187 highlights

3.52.21. StateSettings Chapter 3. Configuration Reference Properties SSLVPNBeforeRules Pass SSL VPN connections sent to the security gateway directly to the SSL VPN engine without consulting the ruleset. (Default: Yes) Note This object type does not have an identifier and is identified by the name of the type only. There can only be one instance of this type. 3.52.21. StateSettings Description Parameters for the state engine in the system. Properties ConnReplace LogOpenFails LogReverseOpens LogStateViolations LogConnections LogConnectionUsage MaxConnections_Dynamic MaxConnections What to do when the connection table is full. (Default: ReplaceLog) Log packets that are neither part of open connections nor valid new connections. (Default: Yes) Log reverse connection attempts through an established connection. (Default: Yes) Log packets that violate stateful tracking rules; for instance, TCP connect sequences. (Default: Yes) Log connections opening and closing. (Default: Log) Log for every packet that passes through a connection. (Default: No) Allocate the Max Connection value dynamically. (Default: Yes) Maximum number of simultaneous connections. (Default: 8192) Note This object type does not have an identifier and is identified by the name of the type only. There can only be one instance of this type. 3.52.22. TCPSettings Description Settings related to the TCP protocol. 187

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198

Properties
SSLVPNBeforeRules
Pass SSL VPN connections sent to the security gate-
way directly to the SSL VPN engine without con-
sulting the ruleset. (Default: Yes)
Note
This object type does not have an identifier and is identified by the name of the type
only. There can only be one instance of this type.
3.52.21. StateSettings
Description
Parameters for the state engine in the system.
Properties
ConnReplace
What
to
do
when
the
connection
table
is
full.
(Default: ReplaceLog)
LogOpenFails
Log packets that are neither part of open connections
nor valid new connections. (Default: Yes)
LogReverseOpens
Log reverse connection attempts through an estab-
lished connection. (Default: Yes)
LogStateViolations
Log packets that violate stateful tracking rules; for
instance, TCP connect sequences. (Default: Yes)
LogConnections
Log connections opening and closing. (Default: Log)
LogConnectionUsage
Log for every packet that passes through a connec-
tion. (Default: No)
MaxConnections_Dynamic
Allocate the Max Connection value dynamically.
(Default: Yes)
MaxConnections
Maximum
number
of
simultaneous
connections.
(Default: 8192)
Note
This object type does not have an identifier and is identified by the name of the type
only. There can only be one instance of this type.
3.52.22. TCPSettings
Description
Settings related to the TCP protocol.
3.52.21. StateSettings
Chapter 3. Configuration Reference
187