HP VPN Firewall Appliances Access Control Command Reference

Table Of Contents
94
Usage guidelines
When the maximum number of concurrent reassemblies is reached, the device discards all subsequent
fragments (not including fragments that belong to assemblies established before the number is reached)
and sends a syslog message. When the maximum number of fragments per reassembly is reached, the
device discards all fragments of the reassembly and sends a syslog. When the fragments of a datagram
(in a reassembly) are not reassembled within the timeout interval, all the fragments of the reassembly are
discarded.
If the drop-fragments keyword is specified along with any combination of the keywords max-fragments,
max-reassemblies, and timeout, the drop-fragment keyword overrides the others and the device drops
all incoming fragments on the interface.
Examples
# Enable IP virtual fragment assemble for security zone Trust.
<Sysname> system-view
[Sysname] zone name trust
[Sysname-zone-trust] ip virtual-reassembly