54
Gateway(config)# no
security vpn-passthrough
l2tp
Disable L2TP passthrough function.
Gateway(config)# no
security vpn-passthrough
pptp
Disable PPTP passthrough function.
Show Command
Gateway(config)# security
vpn-passthrough
Show the current status of VPN
Passthrough.
5. Set up UPnP function
Command
Parameter
Description
Gateway(config)# security
upnp
Enable UPnP function. Universal Plug and
Play (UPnP) is a distributed, open
networking standard that uses TCP/IP for
simple peer-to-peer network connectivity
between devices. An UPnP device can
dynamically join a network, obtain an IP
address, convey its capabilities and learn
about other devices on the network. In
turn, a device can leave a network
smoothly and automatically.
No Command
Gateway(config)# no
security upnp
Disable UPnP function.
6. Set up DDoS function
Command
Parameter
Description
Gateway(config)# security
ddos
Activate DDoS prevention manually. And
select the kinds of DDoS attacks to enable
the Residential Gateway to detect them.
Gateway(config)# security
ddos icmp-smurf
Enable ICMP smurf function to prevent
the hacker to forge the IP address of the
Residential Gateway and send repeated
ping requests to it flooding the network.
Gateway(config)# security
ddos ip-land
Enable IP land function to prevent an
attack which involves a synchronized
request being sent as part of the three
way handshake of TCP to an open port
specifying the port as both the source and
destination effectively locking the port.
Gateway(config)# security
ddos ip-spoof
Enable IP spoof function to prevent a
hacker to create an alias IP address of the
Residential Gateway to which all traffic is
redirected.
Gateway(config)# security
ddos ip-teardrop
Enable to prevent a Teardrop attack. A
Teardrop attack sends mangled IP
fragments with overlapping, over-sized,
payloads to the Residential Gateway. The
fragmented packets are processed by the