This option is for advanced troubleshooting purposes.
After a packet enters the ingress port, it proceeds through several
processing steps before it is parsed for matches against pre‑configured filters. It
is possible for a packet, due to a failure, to not reach the filtering
stage. This can occur, for example, if a route lookup fails. Set
the Pre-Parse Match setting to ON to
emulate a positive match for every packet entering the system. This allows
the firewall to capture packets that do not reach the filtering
process. If a packet is able to reach the filtering stage, it is
then processed according to the filter configuration and discarded
if it fails to meet filtering criteria. |