Filter and Firewall
Left running head:
Chapter name (automatic)
614
Beta
Beta
OmniAccess 700 CLI Command Reference Guide
Alcatel-Lucent
IP
-
ZERO
-
LENGTH
ip-zero-length
D
ESCRIPTION
This attack is caused when the first fragment in the list is of 0-length. This sends a
series of IP fragments such that a 0 length fragment is first in the fragment list.
This makes it impossible for the kernel to deallocate the destination entry and
remove it from the cache. This leads to a system crash. This attack is prevented
by use of the above command.
P
ARAMETERS
None.
E
XAMPLE
ALU(config-firewall-attack-A1)# ip-zero-length
LOG
log
D
ESCRIPTION
Enter this command in the Firewall-Attack Sub Configuration mode. This
command logs all the attacks in the log server.
P
ARAMETERS
None.
E
XAMPLE
ALU(config-firewall-attack-A1)# log
NO
ALL
no all
This command is entered in the Firewall-Attack Sub Configuration mode. The ‘no’
command disables all the attacks configured for an attack object.
NO
ATTACK
no attack
<
name>
This command is entered in the Firewall Configuration mode. This deletes the
specified DoS attack object and its configuration. You cannot delete an attack
object if it is attached to an interface.