L3 Firewall access rules allow you to selectively specify rules for a host (or network) based on which Trellix IPS skips reassembly handling of the fragmented traffic. This helps in decreasing the latency of the fragmented traffic for the specified network or host.
L3 Firewall access rules do not apply to non-fragmented traffic.
It is advisable to use this feature only with a trusted host and only if you are receiving extremely a high amount of fragmented traffic. For example, you could use L3 Firewall access rules if your NFS server is sending a huge amount of fragmented traffic through a Sensor. Note that using this feature while receiving traffic from an unknown host can mean evasion using IP address fragments.
In Trellix IPS, the rules that can be set for L3 Firewall access rules are as follows:
Ignore: Fragmented traffic that matches the L3 Firewall access rules applied is sent inline without reassembly.
Scan: Fragmented traffic that matches the L3 Firewall access rules applied is reassembled prior to IPS processing.
Drop: Fragmented traffic that matches the L3 Firewall access rules applied is dropped by the Sensor.
All fragmented traffic is reassembled before IPS processing if traffic does not match any L3 ACL rules.
In Trellix IPS, three default Service rule objects are provided to support fragmented ICMP, TCP, and UDP. They are ICMP-Fragmented, TCP-Fragmented, and UDP-Fragmented. The user-specified protocol numbers are not supported.
From Manager, you can configure the access rules for fragmented traffic.
Steps:
Select Intrusion Prevention → Policy Types → Firewall.
Click
.On the Properties tab, enter a Name and Description for the policy.
The Owner field corresponds to the admin that you selected.
In the Visibility field, select Owner and Child Domains.
From the Type drop-down, select Advanced or Classic.
Click Next to view the Access Rules tab.
Click the relevant button to insert a new access rule at the appropriate location within the list of access rules.
In the Application section, select the required option from the list.
Select a protocol — ICMP- Fragmented, TCP - Fragmented, or UDP- Fragmented.
When L3 Firewall Access Rules are configured, set TCP Flow Violation to Permit out-of-order (the default setting).
Click the Devices tab.
Select the domain from the Domain drop-down list.
In the left pane, click the Devices tab.
Select the device from the Device drop-down list.
Select Setup → Advanced → Protocol Settings.
In the Protocol Settings page, from the TCP Flow Violation drop-down list, select Permit out-of-order.
Click Update that corresponds to TCP Flow Violation.