|
Avg Bytes/Packet
|
n/a
|
the average number of bytes included in each packet.
|
no
|
|
ECN Flags Normalized in TCP Traffic/Packet
|
enable Explicit Congestion Notification and select Packet
|
the number of packets for which ECN flags have been cleared on a per-packet basis regardless of negotiation.
|
yes
|
|
ECN Flags Normalized in TCP Traffic/Session
|
enable Explicit Congestion Notification and select Stream
|
the number of times that ECN flags have been cleared on a per-stream basis when ECN use was not negotiated.
|
yes
|
|
Events/Sec
|
n/a
|
the number of events per second generated on the device.
|
no
|
|
ICMPv4 Echo Normalizations
|
enable Normalize ICMPv4
|
the number of ICMPv4 packets for which the 8-bit Code field in Echo (Request) or Echo Reply messages were cleared.
|
yes
|
|
ICMPv6 Echo Normalizations
|
enable Normalize ICMPv6
|
the number of ICMPv6 packets for which the 8-bit Code field in Echo (Request) or Echo Reply messages was cleared.
|
yes
|
|
IPv4 DF Flag Normalizations
|
enable Normalize IPv4 and Normalize Don’t Fragment Bit
|
the number of IPv4 packets for which the single-bit Don’t Fragment subfield of the IPv4 Flags header field was cleared.
|
yes
|
|
IPv4 Options Normalizations
|
enable Normalize IPv4
|
the number of IPv4 packets for which the option octet was set to 1 (No Operation).
|
yes
|
|
IPv4 Reserved Flag Normalizations
|
enable Normalize IPv4 and Normalize Reserved Bit
|
the number of IPv4 packets for which the single-bit Reserved subfield of the IPv4 Flags header field was cleared.
|
yes
|
|
IPv4 Resize Normalizations
|
enable Normalize IPv4
|
the number of IPv4 packets with excessive-length payload that have been truncated to the datagram length specified in the
IP header.
|
yes
|
|
IPv4 TOS Normalizations
|
enable Normalize IPv4 and Normalize TOS Bit
|
the number of IPv4 packets for which the one-byte Differentiated Services (DS) field (formerly known as the Type of Service
(TOS) field) was cleared.
|
yes
|
|
IPv4 TTL Normalizations
|
enable Normalize IPv4 , Maximum TTL , and Reset TTL
|
the number of IPv4 Time to Live normalizations.
|
yes
|
|
IPv6 Options Normalizations
|
enable Normalize IPv6
|
the number of IPv6 packets for which the Option Type field in the Hop-by-Hop Options or Destination Options extension header
was set to 00 (Skip and continue processing).
|
yes
|
|
IPv6 TTL Normalizations
|
enable Normalize IPv6 , Minimum TTL , and Reset TTL
|
the number of IPv6 Hop Limit (TTL) normalizations.
|
yes
|
|
Mbits/Sec
|
n/a
|
the number of megabits per second of traffic that passes through the device.
|
no
|
|
Packet Resized to Fit MSS Normalizations
|
enable Trim Data to MSS
|
the number of packets for which the payload was longer than the TCP Data field, so the payload was trimmed to the Maximum
Segment Size.
|
yes
|
|
Packet Resized to Fit TCP Window Normalizations
|
enable Trim Data to Window
|
the number of packets for which the TCP Data field was trimmed to fit the receiving host’s TCP window.
|
yes
|
|
Percent Packets Dropped
|
n/a
|
the average percentage of uninspected packets across all selected devices. For example, if you select two devices, then an
average of 50% may indicate that one device has a 90% drop rate and the other has a 10% drop rate. It may also indicate that
both devices have a drop rate of 50%. The graph only represents the total % drop when you select a single device.
|
no
|
|
RST Packets With Data Stripped Normalizations
|
enable Remove Data on RST
|
the number of packets for which data was removed from a TCP reset (RST) packet.
|
yes
|
|
SYN Packets With Data Stripped Normalizations
|
enable Remove Data on SYN
|
the number of packets for which data was removed from SYN packets when the TCP operating system was not Mac OS.
|
yes
|
|
TCP Header Padding Normalizations
|
enable Normalize/Clear Option Padding Bytes
|
the number of TCP packets in which option padding bytes were set to 0.
|
yes
|
|
TCP No Option Normalizations
|
enable Allow These TCP Options and set to an option other than any
|
the number of packets from which the Time Stamp option was stripped.
|
yes
|
|
TCP NS Flag Normalizations
|
enable Explicit Congestion Notification and select Packet
|
the number of ECN Nonce Sum (NS) option normalizations.
|
yes
|
|
TCP Options Normalizations
|
enable Allow These TCP Options and set to an option other than any
|
the number of options (excluding MSS, Window Scale, Time Stamp, and explicitly allowed options) for which the option field
is set to No Operation (TCP Option 1).
|
yes
|
|
TCP Packets Blocked By Normalizations
|
enable Normalize TCP Payload (segment reassembly must fail)
|
the number of packets dropped because the TCP segments could not be properly reassembled.
|
yes
|
|
TCP Reserved Flags Normalizations
|
enable Normalize/Clear Reserved Bits
|
the number of TCP packets where the Reserved bits have been cleared.
|
yes
|
|
TCP Segment Reassembly Normalizations
|
enable Normalize TCP Payload (segment reassembly must be successful)
|
the number of packets for which the TCP Data field was normalized to ensure consistency in retransmitted data (any segments
that cannot be properly reassembled are dropped).
|
yes
|
|
TCP SYN Option Normalizations
|
enable Allow These TCP Options and set to an option other than any
|
the number of options for which the Maximum Segment Size or Window Scale option was set to No Operation (TCP Option 1) because
the SYN control bit was not set.
|
yes
|
|
TCP Timestamp ECR Normalizations
|
enable Allow These TCP Options and set to an option other than any
|
the number of packets for which the Time Stamp Echo Reply (TSecr) option field was cleared because the Acknowledgment (ACK)
control bit was not set.
|
yes
|
|
TCP Urgent Pointer Normalizations
|
enable Normalize Urgent Pointer
|
the number of packets for which the two-byte TCP header Urgent Pointer field was greater than the payload length and was set
to the payload length.
|
yes
|
|
Total Blocked Packets
|
configure Inline Mode or Drop when Inline
|
the total number of dropped packets, including rule, decoder, and preprocessor drops.
|
no
|
|
Total Injected Packets
|
configure Inline Mode
|
the number of packets that were resized before being retransmitted.
|
no
|
|
Total TCP Filtered Packets
|
configure TCP Stream Preprocessing
|
the number of packets skipped by the stream because of TCP port filtering.
|
no
|
|
Total UDP Filtered Packets
|
configure UDP Stream Preprocessing
|
the number of packets skipped by the stream because of UDP port filtering.
|
no
|
|
Urgent Flag Cleared Normalizations
|
enable Clear URG if Urgent Pointer is Not Set
|
the number of packets for which the TCP header URG control bit was cleared because the urgent pointer was not set.
|
yes
|
|
Urgent Pointer and Urgent Flag Cleared Normalizations
|
enable Clear Urgent Pointer/URG on Empty Payload
|
the number of packets for which the TCP header Urgent Pointer field and the URG control bit have been cleared because there
was no payload.
|
yes
|
|
Urgent Pointer Cleared Normalizations
|
enable Clear Urgent Pointer if URG=0
|
the number of packets for which the 16-bit TCP header Urgent Pointer field was cleared because the urgent (URG) control bit
was not set.
|
yes
|