tcp-null-scan
Except on the first page, right running head:
Heading1 or Heading1NewPage text (automatic)
627
Alcatel-Lucent
Beta
Beta
OmniAccess 700 CLI Command Reference Guide
TCP
-
NULL
-
SCAN
tcp-null-scan
D
ESCRIPTION
TCP packets without any flag set. Leads to inability to scan such packets. This
attack can also be avoided by including this command in the user-defined
prevention list or by the “default” keyword.
P
ARAMETERS
None.
E
XAMPLE
ALU(config-firewall-attack-A1)# tcp-null-scan
TCP
-
SYN
-
FIN
tcp-syn-fin
D
ESCRIPTION
It has TCP packets with both SYN and FIN flag set, causing a denial of service.
The above keyword is also turned on by default. If you wish to disable this, you
can override this keyword and then turn it on when necessary by including this
command in the user-defined attack prevention list.
P
ARAMETERS
None.
E
XAMPLE
ALU(config-firewall-attack-A1)# tcp-syn-fin