D-Link DFL-800 CLI Guide - Page 145

Block 127.* source addresses. Default: DropLog

Page 145 highlights

3.43.8. IPSettings Chapter 3. Configuration Reference IKEMaxCAPath IPsecCertCacheMaxCerts IPsecBeforeRules IPsecGWNameCacheTime DPDMetric DPDKeepTime DPDExpireTime Maximum number of CA certificates in a certificate path. (Default: 15) Maximum number of entries in the certificate cache. (Default: 1024) Pass IKE & IPsec (ESP/AH) traffic sent to the security gateway directly to the IPsec engine without consulting the ruleset. (Default: Yes) Amount of time to keep an IPsec tunnel open when the remote DNS name fails to resolve. (Default: 14400) Metric 10s of seconds with no traffic or other evidence of life in tunnel before SA is removed. (Default: 3) Number 10s of seconds a SA will remain in dead cache after a delete. DPD will not trigger if peer already is cached as dead. (Default: 2) Number of seconds that DPD-R-U-THERE messages will be sent. (Default: 15) Note This object type does not have an identifier and is identified by the name of the type only. There can only be one instance of this type. 3.43.8. IPSettings Description Settings related to the IP protocol. Properties LogCheckSumErrors LogNonIP4 LogReceivedTTL0 Block0000Src Block0Net Block127Net BlockMulticastSrc TTLMin TTLOnLow TTLMinMulticast Log IP packets with bad checksums. (Default: Yes) Log occurrences of non-IPv4 packets. (Default: Yes) Log received packets with TTL=0; this should never happen! (Default: Yes) Block 0.0.0.0 as source address. (Default: Drop) Block 0.* source addresses. (Default: DropLog) Block 127.* source addresses. (Default: DropLog) Block multicast source addresses (224.0.0.0--255.255.255.255). (Default: DropLog) The minimum IP Time-To-Live value accepted on receipt. (Default: 3) What action to take on too low unicast TTL values. (Default: DropLog) The minimum IP multicast Time-To-Live value accepted on 145

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166

IKEMaxCAPath
Maximum number of CA certificates in a certificate path.
(Default: 15)
IPsecCertCacheMaxCerts
Maximum number of entries in the certificate cache. (Default:
1024)
IPsecBeforeRules
Pass IKE & IPsec (ESP/AH) traffic sent to the security gate-
way directly to the IPsec engine without consulting the ruleset.
(Default: Yes)
IPsecGWNameCacheTime
Amount of time to keep an IPsec tunnel open when the remote
DNS name fails to resolve. (Default: 14400)
DPDMetric
Metric 10s of seconds with no traffic or other evidence of life
in tunnel before SA is removed. (Default: 3)
DPDKeepTime
Number 10s of seconds a SA will remain in dead cache after a
delete. DPD will not trigger if peer already is cached as dead.
(Default: 2)
DPDExpireTime
Number of seconds that DPD-R-U-THERE messages will be
sent. (Default: 15)
Note
This object type does not have an identifier and is identified by the name of the type
only. There can only be one instance of this type.
3.43.8. IPSettings
Description
Settings related to the IP protocol.
Properties
LogCheckSumErrors
Log IP packets with bad checksums. (Default: Yes)
LogNonIP4
Log occurrences of non-IPv4 packets. (Default: Yes)
LogReceivedTTL0
Log received packets with TTL=0; this should never happen!
(Default: Yes)
Block0000Src
Block 0.0.0.0 as source address. (Default: Drop)
Block0Net
Block 0.* source addresses. (Default: DropLog)
Block127Net
Block 127.* source addresses. (Default: DropLog)
BlockMulticastSrc
Block
multicast
source
addresses
(224.0.0.0--255.255.255.255). (Default: DropLog)
TTLMin
The minimum IP Time-To-Live value accepted on receipt.
(Default: 3)
TTLOnLow
What action to take on too low unicast TTL values. (Default:
DropLog)
TTLMinMulticast
The minimum IP multicast Time-To-Live value accepted on
3.43.8. IPSettings
Chapter 3. Configuration Reference
145