Some attacks from the Internet try to outsmart the Firewall by fragmented packets (packets split into several small units). One of the main features of a Stateful Inspection like in the LANCOM is the ability to re-assemble fragmented packets in order to check afterwards the entire IP packet.
You can centrally adjust the desired behavior of the Firewall. The following options are available:
- Filter: Fragmented packets are directly discarded by the Firewall.
- Route: Fragmented packets are passed on without any further checking by the Firewall, as long as permitted by valid filter settings.
- Re-assemble: Fragmented packets are buffered and re-assembled to complete IP packets. The re-assembled packets will then be checked and treated according to the valid filter settings.