User's Manual Part 4

Page 22 SonicWALL SonicOS Standard Administrator’s Guide
Detection Prevention
Enable Stealth Mode
By default, the SonicWALL responds to incoming connection requests as either “blocked” or “open”. If you
enable Stealth Mode, your SonicWALL does not respond to blocked inbound connection requests.
Stealth Mode makes your SonicWALL essentially invisible to hackers.
Randomize IP ID
Select Randomize IP ID to prevent hackers using various detection tools from detecting the presence of
a SonicWALL appliance. IP packets are given random IP IDs which makes it more difficult for hackers to
“fingerprint” the SonicWALL appliance.
Dynamic Ports
•Select Enable support for Oracle (SQLNet) if you have Oracle applications on your network.
•Select Enable Support for Windows Messenger if you are having problems using Windows Mes-
senger and Windows XP through the SonicWALL. If Enable Support for Windows Messenger is
selected, it may affect the performance of the SonicWALL.
•Select Enable SIP Transformations to transform SIP messaging from the LAN to the WAN. If the
SIP proxy is located on the WAN and the SIP clients are on the LAN, the SIP clients use their private
IP address in the SIP Session Definition Protocol (SDP) sent to the SIP proxy. Since the IP addresses
are unchanged, the SIP proxy cannot return messages to the SIP client. By enabling SIP transforma-
tions on the SonicWALL, the appliance changes the private address and port in the SDP to the public
address and port. The SIP transformation also controls and opens the RTP/RTCP ports to allow SIP
sessions.
•Select Enable H.323 Transformations for H.323 protocol-aware packet content inspection and mod-
ification by the SonicWALL. The SonicWALL performs any dynamic IP address and transport port
mapping, within the H.323 packet, necessary for communication between H.323 parties on the LAN
and WAN.
•Select Enable RTSP Transformations to support on-demand delivery of real-time data, such as au-
dio and video. RTSP (Real Time Streaming Protocol) is an application-level protocol for control over
delivery of data with real-time properties.
Source Routed Packets
Drop Source Routed Packets is selected by default. Clear the check box if you are testing traffic
between two specific hosts and you are using source routing.
TCP Connection Inactivity Timeout
If a connection to a remote server remains idle for more than five minutes, the SonicWALL closes the
connection. Without this timeout, Internet connections could stay open indefinitely, creating potential
security holes. You can increase the Inactivity Timeout if applications, such as Telnet and FTP, are
frequently disconnected.

Summary of content (80 pages)