TMS zl Management and Configuration Guide ST.1.1.100226
B-23
Glossary
PEM Privacy Enhanced Mail. An IETF proposal to secure emails with public keys.
PEM depends on prior distribution of a hierarchical PKI with a single root. For
more information, see RFCs 1421–1424 at http://www.ietf.org/rfc.html.
per-hop behavior See PHB.
perfect forward
secrecy
See PFS.
persistent tunnel An IPsec SA configured as a persistent tunnel always remains open. It is
renewed even if it remains inactive longer than the tunnel lifetime.
PFS Perfect Forward Secrecy. A key-establishment protocol that is used to secure
VPN connections, wherein the key that was used to protect the transmission
of data is not used to derive any additional keys.
PHB Per-Hop Behavior. Defines how packets are queued at network nodes.
PIM-SM Protocol Independent Multicast sparse mode. A protocol used to efficiently
route traffic to multicast groups that span wide-area (WAN and inter-domain)
internets. For more information, see RFCs 2365 at www.ietf.org/rfc/
rfc2362.txt.
ping of death An attack in which the attacker sends a ping packet that is larger than 65535
bytes. Ping packets this large cause the victim device to crash, causing a DoS.
PMTU Path Maximum Transmission Unit. A technique for detecting the maximum
size for an IP packet along a particular path. For more information, see RFC
1191 at http://www.ietf.org/rfc/rfc1191.txt.
poison reverse In RIP, a poison reverse message tells a router that a route in the routing table
is no longer connected. This helps to speed convergence.
policy group A set of policies (firewall or NAT) that have the same source and destination
zones.
polymorphism The capability of an object to assume more than one property, often shifting
from one property to another in response to external stimuli.
port address
translation
See PAT.
port forwarding The process in which traffic addressed to one port is forwarded to a different
port. Port forwarding is often employed when a network is running well-
known protocols on non-standard ports.
port map A port-to-application association that informs the IDS/IPS and ALGs which type
of traffic to expect on a particular port.