D-Link DFL-800 CLI Guide - Page 146

PPTP/L2TP server settings.

Page 146 highlights

3.43.9. L2TPServerSettings Chapter 3. Configuration Reference TTLOnLowMulticast DefaultTTL LayerSizeConsistency SecuRemoteUDPEncapCompat IPOptionSizes IPOPT_SR IPOPT_TS IPOPT_RTRALT IPOPT_OTHER DirectedBroadcasts IPRF StripDFOnSmall MulticastIPEnetOnMismatch receipt. (Default: 3) What action to take on too low multicast TTL values. (Default: DropLog) The default IP Time-To-Live of packets originated by the security gateway (32-255). (Default: 255) TCP/UDP/ICMP/etc layer data and header sizes matching lower layer size information. (Default: ValidateLogBad) Allow IP data to contain eight bytes more than the UDP total length field specifies -- Checkpoint SecuRemote violates NAT-T drafts. (Default: No) Validity of IP header option sizes. (Default: ValidateLogBad) How to handle IP packets with contained source or return routes. (Default: DropLog) How to handle IP packets with contained Timestamps. (Default: DropLog) How to handle IP packets with contained route alert. (Default: ValidateLogBad) How to handle IP options not specified above. (Default: DropLog) How to handle directed broadcasts being passed from one interface to another. (Default: DropLog) How to handle the IP Reserved Flag, if set; it should never be. (Default: DropLog) Strip the "DontFragment" flag for packets of this size or smaller. (Default: 65535) What action to take when ethernet and IP multicast addresses does not match. (Default: DropLog) Note This object type does not have an identifier and is identified by the name of the type only. There can only be one instance of this type. 3.43.9. L2TPServerSettings Description PPTP/L2TP server settings. Properties L2TPBeforeRules PPTPBeforeRules Pass L2TP connections sent to the security gateway directly to the L2TP engine without consulting the ruleset. (Default: Yes) Pass PPTP connections sent to the security gateway directly to the PPTP engine without consulting the ruleset. (Default: Yes) 146

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166

receipt. (Default: 3)
TTLOnLowMulticast
What action to take on too low multicast TTL values.
(Default: DropLog)
DefaultTTL
The default IP Time-To-Live of packets originated by the se-
curity gateway (32-255). (Default: 255)
LayerSizeConsistency
TCP/UDP/ICMP/etc layer data and header sizes matching
lower layer size information. (Default: ValidateLogBad)
SecuRemoteUDPEncapCompat
Allow IP data to contain eight bytes more than the UDP total
length field specifies -- Checkpoint SecuRemote violates
NAT-T drafts. (Default: No)
IPOptionSizes
Validity of IP header option sizes. (Default: ValidateLogBad)
IPOPT_SR
How to handle IP packets with contained source or return
routes. (Default: DropLog)
IPOPT_TS
How
to
handle
IP
packets
with
contained
Timestamps.
(Default: DropLog)
IPOPT_RTRALT
How to handle IP packets with contained route alert. (Default:
ValidateLogBad)
IPOPT_OTHER
How to handle IP options not specified above. (Default:
DropLog)
DirectedBroadcasts
How to handle directed broadcasts being passed from one in-
terface to another. (Default: DropLog)
IPRF
How to handle the IP Reserved Flag, if set; it should never be.
(Default: DropLog)
StripDFOnSmall
Strip the "DontFragment" flag for packets of this size or smal-
ler. (Default: 65535)
MulticastIPEnetOnMismatch
What action to take when ethernet and IP multicast addresses
does not match. (Default: DropLog)
Note
This object type does not have an identifier and is identified by the name of the type
only. There can only be one instance of this type.
3.43.9. L2TPServerSettings
Description
PPTP/L2TP server settings.
Properties
L2TPBeforeRules
Pass L2TP connections sent to the security gateway directly to the L2TP
engine without consulting the ruleset. (Default: Yes)
PPTPBeforeRules
Pass PPTP connections sent to the security gateway directly to the PPTP
engine without consulting the ruleset. (Default: Yes)
3.43.9. L2TPServerSettings
Chapter 3. Configuration Reference
146