User`s guide
346
UDP s seconds
The value in this text box specifies the length of time that a stateful inspection rule will
remain in place following the receipt of UDP packet. The timer is restarted each time
packets matching the rule pass in each direction. As a consequence, rules based on UDP
should only be used if it anticipated that packets will travel in both directions.
ICMP s seconds
Some ICMP packets – for instance the ECHO request – generate response packets. The
value in this text box specifies the length of time that a stateful inspection rule created for
an ICMP packet will remain in place if the response is not received. The rule is removed
immediately following receipt of the response.
Other protocols s seconds
If a stateful inspection rule is created from a packet type other than TCP, UDP or ICMP, a
rule timeout should be created for it. The parameter in this text box specifies the length of
time such a rule persists. The timer is restarted each time a packet is processed by the rule.
Other Options
Expire entry after n consecutive packets in one direction
The value in this text box specifies the maximum number of consecutive packets that should
pass in one direction before the corresponding rule entry is expired.
Count missed UDP echo packets as dropped
When checked, this checkbox will cause the firewall to increment the dropped packet count
for each failed echo request in the situation where UDP echo is active on an interface that
becomes disconnected.
Related CLI Commands
Entity
Instance
Parameter
Values
Equivalent Web Parameter
fwall 0 opening 0 - 4294967296 TCP Opening s seconds
fwall 0 open 0 – 4294967296 TCP Open s seconds
fwall 0 closing 0 - 4294967296 TCP Closing s seconds
fwall 0 closed 0 – 4294967296 TCP Closed s seconds
fwall 0 udp 0 – 4294967296 UDP s seconds
fwall 0 icmp 0 – 4294967296 ICMP s seconds
fwall 0 other 0 – 4294967296 Other protocols s seconds
fwall 0 maxuni 0 - 2147483647
Expire entry after n consecutive
packets in one direction
fwall 0 cntmissedecho
OFF,ON
Default OFF
Count missed UDP echo packets
as dropped