Create a customized Engine Template Policy
For a Common Criteria installation, add specific Access rules to a customized Engine Template Policy, then use that template to create security policies.
These steps are the high-level tasks. For more information, see the Creating and managing policy elements chapter in the Forcepoint Network Security Platform Product Guide.
Packet validity checks automatically drop invalid IP packets, packets with certain IP options, incomplete IP packets, and invalid IP fragments. These dropped packets are also logged when Packet Filter diagnostics have been enabled. The automatic anti-spoofing drops and logs spoofed packets where the source or the destination address is a loopback address, the source address is an IPv4 broadcast address or an IPv4 multicast address, or the source address does not belong to a connected network. The additional Access rules in the customized template discard IPv4 and IPv6 link local addresses, IPv6 reserved addresses, IPv4 and IPv6 addresses reserved for future use, and packets where the source address is an IPv6 multicast address.
For more details about the product and how to configure features, click Help or
press F1.