M
ANAGEMENT
I
NTERFACE
3.6. Security
3.6.1 Denial of Service Protection
The Denial of Service Configuration page allows users to enable or disable denial of
service settings. To access this page, click
Security
>
Denial of Service Protection
.
Figure 3-151.
Security > Denial of Service Protection
The following table describes the items in the previous menu.
Table 3-148.
Security > Denial of Service Protection
Parameter
Description
Denial of Service
Click the drop-down menu to enable or disable the option by selecting the corre-
SIP=DIP
sponding line on the pull-down entry field. Enabling SIP=DIP DoS prevention
causes the switch to drop packets that have a source IP address equal to the des-
tination IP address. The factory default is Disable.
Denial of Service
Click the drop-down menu to enable or disable the option by selecting the corre-
SMAC=DMAC
sponding line on the pull-down entry field. Enabling SMAC=DMAC DoS prevention
causes the switch to drop packets that have a source MAC address equal to the
destination MAC address. The factory default is Disable.
Denial of Service
Click the drop-down menu to enable or disable the option by selecting the corre-
TCP Flag
sponding line on the pull-down entry field. Enabling TCP Flag DoS prevention
causes the switch to drop packets that have TCP flag SYN set and TCP source
port less than 1024 or TCP control flags set to 0 and TCP sequence number set to
0 or TCP flags FIN, URG, and PSH set and TCP sequence number set to 0 or both
TCP flags SYN and FIN set. The factory default is Disable.
Denial of Service
Click the drop-down menu to enable or disable the option by selecting the corre-
TCP Fragment
sponding line on the pull-down entry field. Enabling TCP Fragment DoS prevention
causes the switch to drop packets that have an IP fragment offset equal to 1. The
factory default is Disable.
Denial of Service L4
Click the drop-down menu to enable or disable the option by selecting the corre-
Port
sponding line on the pull-down entry field. Enabling L4 Port DoS prevention causes
the switch to drop packets that have TCP/UDP source port equal to TCP/UDP des-
tination port. The factory default is Disable.
Submit
Click
Submit
to update the switch with the values on the screen. If you want the
switch to retain the new values across a power cycle you must perform a save.
198
Summary of Contents for EKI-9312P Series
Page 13: ...Hardware Installation Chapter 1...
Page 43: ...First Time Setup Chapter 2...
Page 48: ...Management Interface Chapter 3...
Page 285: ...Troubleshooting Chapter 4...