Advanced

Keep classification after encapsulation

Select this checkbox if you want to make sure that after encapsulation a packet will still match the traffic selector of the original service if no other traffic selector matches.

The assignment of an encapsulated IP packet to a traffic selector works as follows:

  1. The original IP packet is compared with the existing traffic selectors in the given order. The packet is assigned to the first matching traffic selector (e.g., Internal -> HTTP -> Any).
  2. The IP packet gets encapsulated, and the service changes (e.g., to IPsec).
  3. The encapsulated packet is compared with the existing traffic selectors in the given order. The packet is assigned to the first matching traffic selector (e.g., Internal -> IPsec -> Any).
  4. If no traffic selector matches, the assignment depends on the Keep classification after encapsulation option:

Explicit Congestion Notification support

ECNClosed (Explicit Congestion Notification) is an extension to the Internet Protocol and allows end-to-end notifications of network congestion without dropping packets. ECN only works if both endpoints of a connection successfully negotiate to use it. Selecting this checkbox, Sophos UTM will send the information that it is willing to use ECN. If the other endpoint agrees, they will exchange ECN information. Note that the underlying network and involved routers must support ECN as well.

© 2019 Sophos Limited Sophos UTM 9.600