![Alcatel-Lucent OmniAccess 700 Cli Configuration Manual Download Page 698](http://html.mh-extra.com/html/alcatel-lucent/omniaccess-700/omniaccess-700_cli-configuration-manual_2891856698.webp)
Filter and Firewall
Left running head:
Chapter name (automatic)
672
Beta
Beta
CLI Configuration Guide
Alcatel-Lucent
TCP
-
FIN
-
NO
-
ACK
tcp-fin-no-ack
TCP packets without ACK set for FIN.This leads to system crashing at times. To
avoid this mishap, the above command is also present in the default DoS
prevention list.
TCP
-
INVALID
-
URGENT
-
OFFSET
tcp-invalid-urgent-offset
The intruder sends a TCP frame with an Urgent pointer which points past the end
of the data. This may cause some TCP/IP implementations to become unstable or
crash. Some TCP/IP implementations will hang when receiving many such
frames. Inclusion of this command avoids such attacks.
TCP
-
NULL
-
SCAN
tcp-null-scan
TCP packets w/o any flag set. Leads to inability to scan such packets. This attack
is avoided since it is also included in the default DoS prevention list.
TCP
-
SYN
-
FIN
tcp-syn-fin
This has TCP packets with both SYN and FIN flag set, causing a denial of service.
This attack is prevented by using the “default” keyword or can be inserted in the
user-defined list.
TCP
-
XMAS
-
SCAN
tcp-xmas-scan
This frame should never be seen in normal TCP operation. Sometimes this is
done in preparation for a future attack, or sometimes it is done to see if the system
has a service which is susceptible to attack. A TCP frame has been seen with a
sequence number of zero and the FIN, URG, and PUSH bits all set. To avoid this
attack the above command is placed in the default DoS prevention list.
UDP
-
FRAGGLE
-
ATTACK
udp-fraggle-attack
When a perpetrator sends a large number of UDP echo (ping) traffic at IP
broadcast addresses, all of it having a fake source address, it causes system
crash or denial of service. This command is implicitly included in the default attack
prevention list to secure the system from this attack.
Summary of Contents for OmniAccess 700
Page 38: ...Left running head Chapter name automatic 12 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Page 176: ...Left running head Chapter name automatic 150 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Page 260: ...Left running head Chapter name automatic 234 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Page 434: ...Left running head Chapter name automatic 408 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Page 464: ...Left running head Chapter name automatic 438 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Page 638: ...Left running head Chapter name automatic 612 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Page 940: ...Left running head Chapter name automatic 914 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Page 1002: ...Left running head Chapter name automatic 976 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Page 1120: ...Left running head Chapter name automatic 2 Beta Beta CLI Configuration Guide Alcatel Lucent ...