Configuring
IP Fragment Reassembly
To configure IP fragment reassembly, follow these steps:
-
Select the Sensing tab on the sensor you
want to configure.
-
Check the Reassemble Fragments check box
(refer to Figure 7.22).
Figure 7.22: The Sensing Tab
-
Enter the settings for Maximum Partial
Datagrams, Maximum Fragments Per Datagram, and Fragmented Datagram Timeout.
-
Once you have finished configuring the Sensing parameters,
click OK, then save and update your configuration.
-
From the Command tab, click Approve Now to push the new configuration to your sensor.
|
Note |
Cisco's recommended guidelines for determining the maximum
partial datagrams and maximum fragments per datagram is as follows (it takes a
little math here):
-
The partial datagrams multiplied by the fragments per
datagram should be less than 2,000,000. This applies to all 4200 series sensors
running versions 2.2.1.5 or 2.5(X).
-
The partial datagrams multiplied by the
fragments per datagram should be less than 5000. This applies to the IDSMs
running versions 2.5(X). |