Review this section to know how some of the features work with respect to jumbo frames.
IPS attack detection — The Sensor detects all attack types (Reconnaissance, DoS, Exploit, HTTP response-based attacks etc) in jumbo frames for both IPv4 and IPv6 traffic. Attacks are also detected in fragmented and non-fragmented jumbo frames with VLAN, double VLAN and MPLS header. The Sensor detects attacks in fragmented jumbo frames up to 9216 bytes (9KB) in the IPv4/IPv6 traffic.
The IPS Sensor interface type can be of any type such as dedicated, VLAN, and so on.
Note that the Sensor also detects attacks in jumbo frames targeted to the non-standard ports.
According to the configured attack response actions, the Sensor responds or blocks the packets. Alerts are raised in the Attack Log as with the standard Ethernet frames.
SSL decryption — When SSL decryption is enabled in the sensor, the jumbo frame traffic with SSL encryption will be decrypted.
Malware detection — When jumbo frame parsing is enabled, the Sensor uses various methods to inspect files being downloaded for embedded malware. If a malware is detected, the Sensor blocks the download and takes further response actions.
Trellix Custom Attack detection — The Sensor detects custom attacks in jumbo frames and alerts are raised in the Attack Log.
IP Spoofing detection — The Sensor drops IP spoofed packet received in a jumbo frame.
Fail-open and fail-close modes — The Sensor supports fail-open and fail-closed modes for jumbo frames.
Traffic management — If the jumbo frames are of size less than 9,216 bytes, the Sensor implements the QoS policies for DiffServ tagging and VLAN 802.1p tagging.
Syn cookie handling — When SYN cookie is enabled on the Sensor in conjunction with jumbo frame parsing, you may experience TCP segmentation for application with payloads greater than the Sensor-advertised MSS, resulting in non-jumbo frames even if the network path supports jumbo frames. This will result in performance degradation since the endpoints exchange non-jumbo frames in spite of the network path supporting jumbo frames.
Firewall policies — When jumbo frame parsing is enabled in the Sensor, Firewall access rules are applied as configured for jumbo frames of size up to 9216 bytes (9KB).
Snort Custom Attack detection — When jumbo frame parsing and Snort are enabled, the Sensor detects Snort attacks (if any) in the jumbo frames. Attacks are also detected in fragmented jumbo frames where the Snort signature falls in more than one fragment.
GRE tunneled traffic — When the tunnel configuration and jumbo frame parsing are enabled, the Sensor performs IPS detection on the GRE-tunneled traffic received as jumbo frames.
Jumbo frame parsing is also supported with quarantine, port clustering, fail-over, layer 2 mode, malware analysis, and Sensor performance monitoring.