Sensors have the intelligence to keep a number of TCP/IP connection parameters, as well as complete state information. The Devices → <Domain name> → Devices → <Device Name> → Setup → Advanced → Protocol Settings and Devices → <Domain name> → Devices → <Device Name> → Setup → Advanced → IP Settings action enables you to configure 16 TCP/IP parameters, such as the number of supported UDP flows, the TCB inactivity timer length, and accepting old data or new data for TCP or IP overlaps. All of the TCP/IP Settings parameters relate to the handling of monitored transmissions while in inline mode. You can use these settings to deny or drop certain traffic.
Two of the more notable parameters are as follows:
Cold Start Drop Action — When starting a Sensor for the first time, you can decide to allow (forward) or drop all packets that do not have a flow control block recognized by the Sensor. You have the choice to Forward Flows or Drop Flows.
TCP Flow Violation — This helps you determine to handle a packet received for a connection that does not exist, such as an ACK packet when no SYN for a connection has been received. Choices are as follows:
Permit — Reassembles out-of-order packets and processes them. It forwards traffic if strict TCP protocol violations and if State Not Established on Sensor fails.
Permit out-of-order — Allows out of order packets to continue to transmit without processing
Deny — Checks the flow for strict TCP protocol violations; if it discovers violations, it drops the packet and reassembles out-of-order packets.
Deny no TCB — (Deny if state is not established) drops the session only if the state has not been established. It forwards traffic only if strict TCP protocol violations fails.
Stateless Inspection — Does not consider the flow for inspection
Note
If malware analysis is configured, select Permit as the malware analysis requires all packets to construct the file.
If asymmetric routing is configured in your environment, select Stateless Inspection or Permit out-of-order. Using Permit can cause the packets to be held for TCP segment reassembly and subsequent timeouts which might result in higher latency.
For more information about standalone and HA pair of Sensors with asymmetric traffic, refer to Asymmetric traffic handling.