User Manual

Using SmartDefense
Chapter 9: Setting Your Security Policy 229
IP and ICMP
This category allows you to enable various IP and ICMP protocol tests, and to
configure various protections against IP and ICMP-related attacks. It includes the
following:
Packet Sanity on page
229
Max Ping Size on page
231
IP Fragments on page 232
Network Quota on page
234
Welchia on page 235
Cisco IOS DOS on page 236
Null Payload on page
238
Packet Sanity
Packet Sanity performs several Layer 3 and Layer 4 sanity checks. These include
verifying packet size, UDP and TCP header lengths, dropping IP options, and
verifying the TCP flags.
You can configure whether logs should be issued for offending packets.