Security
Denial of Service Prevention
374
Cisco 350, 350X and 550X Series Managed Switches, Firmware Release 2.4, ver 0.4
17
-
Prefix Length
—Select the Prefix Length and enter the number of bits that comprise
the source IP address prefix.
•
SYN Rate Limit
—Enter the number of SYN packets that be received.
STEP 4
Click
Apply
. The SYN rate protection is defined, and the Running Configuration is updated.
ICMP Filtering
The ICMP Filtering page enables the blocking of ICMP packets from certain sources. This can
reduce the load on the network in case of an ICMP attack.
To define ICMP filtering:
STEP 1
Click
Security
>
Denial of Service Prevention
>
ICMP Filtering
.
STEP 2
Click
Add
.
STEP 3
Enter the parameters.
•
Interface
—Select the interface on which the ICMP filtering is being defined.
•
IP Address
—Enter the IPv4 address for which the ICMP packet filtering is activated
or select
All Addresses
to block ICMP packets from all source addresses. If you enter
the IP address, enter either the mask or prefix length.
•
Network Mask
—Select the format for the subnet mask for the source IP address, and
enter a value in one of the field:
-
Mask
—Select the subnet to which the source IP address belongs and enter the
subnet mask in dotted decimal format.
-
Prefix Length
—Select the Prefix Length and enter the number of bits that comprise
the source IP address prefix.
STEP 4
Click
Apply
. The ICMP filtering is defined, and the Running Configuration is updated.
IIP Fragments Filtering
The IP Fragmented page enables blocking fragmented IP packets.