xStack
®
DGS-3120 Series Layer 3 Managed Gigabit Ethernet Switch CLI Reference Guide
286
Chapter 23
Denial-of-Service (DoS)
Attack Prevention
Command List
config dos_prevention dos_type
[{land_attack | blat_attack | tcp_null_scan | tcp_xmasscan |
tcp_synfin | tcp_syn_srcport_less_1024 | ping_death_attack | tcp_tiny_frag_attack}(1) | all]
{action [drop] | state [enable | disable]}(1)
show dos_prevention
{land_attack | blat_attack | tcp_null_scan | tcp_xmasscan | tcp_synfin |
tcp_syn_srcport_less_1024 | ping_death_attack | tcp_tiny_frag_attack}
config dos_prevention trap
[enable | disable]
config dos_prevention log
[enable | disable]
23-1
config dos_prevention dos_type
Description
This command is used to prevent the DoS attack from specific ports.
Format
config dos_prevention dos_type [{land_attack | blat_attack | tcp_null_scan | tcp_xmasscan
| tcp_synfin | tcp_syn_srcport_less_1024 | ping_death_attack | tcp_tiny_frag_attack}(1) | all]
{action [drop] | state [enable | disable]}(1)
Parameters
land_attack
- Specify the type of DoS attack as land attack.
blat_attack
- Specify the type of DoS attack as blat attack.
tcp_null_scan
- Specify the type of DoS attack as TCP null scan.
tcp_xmasscan
- Specify the type of DoS attack as TCP xmasscan.
tcp_synfin
- Specify the type of DoS attack as TCP synfin.
tcp_syn_srcport_less_1024
- Specify the type of DoS attack as tcp_syn_srcport_less_1024.
ping_death_attack
- Specify the type of DoS attack as ping_death_attack.
tcp_tiny_frag_attack
- Specify the type of DoS attack as tcp_tiny_frag_attack.
all
- Specify all types of DoS attack.
action
- When the DoS prevention is enabled, the following action can be taken.
drop
- Drop DoS attack packets.
state
- Specify the DoS attack prevention state.
enable
- Enable the DoS attack prevention.
disable
- Disable the DoS attack prevention.
Restrictions
Only Administrator, Operator and Power-User level users can issue this command.
Example
To configure land attack and blat attack prevention, the action is drop:
Summary of Contents for xStack DGS-3120-24PC
Page 1: ......
Page 186: ...xStack DGS 3120 Series Layer 3 Managed Gigabit Ethernet Switch CLI Reference Guide 181 ...
Page 204: ...xStack DGS 3120 Series Layer 3 Managed Gigabit Ethernet Switch CLI Reference Guide 199 ...
Page 363: ...xStack DGS 3120 Series Layer 3 Managed Gigabit Ethernet Switch CLI Reference Guide 358 ...
Page 1056: ...xStack DGS 3120 Series Layer 3 Managed Gigabit Ethernet Switch CLI Reference Guide 1051 ...