User Manual
Using SmartDefense
Chapter 9: Setting Your Security Policy 229
IP and ICMP
This category allows you to enable various IP and ICMP protocol tests, and to
configure various protections against IP and ICMP-related attacks. It includes the
following:
• Packet Sanity on page
229
• Max Ping Size on page
231
• IP Fragments on page 232
• Network Quota on page
234
• Welchia on page 235
• Cisco IOS DOS on page 236
• Null Payload on page
238
Packet Sanity
Packet Sanity performs several Layer 3 and Layer 4 sanity checks. These include
verifying packet size, UDP and TCP header lengths, dropping IP options, and
verifying the TCP flags.
You can configure whether logs should be issued for offending packets.