Configuring Access Control Lists
639
A Consolidated DoS Example
This example includes some ACL rules to consider to reduce DoS attacks on
the switch. It does not represent a complete DoS suite. A firewall with deep
packet inspection capabilities should be used for true DoS protection.
ip access-list reduce-dos-attacks
!
! Rate limit echo requests
!
permit icmp any any icmp-message echo rate-limit 32 64
!
! Deny telnet and rate-limit SSH to the CPU
!
deny tcp any any eq telnet flag established
permit tcp any any eq 22 flag established rate-limit 1024 128
deny tcp any any eq telnet
permit tcp any any eq 22 rate-limit 12 2
!
! Rate limit TCP opens
!
permit tcp any any flag +syn rate-limit 8 2
!
! Rate limit TCP closes
!
permit tcp any any flag +fin rate-limit 8 2
!
! Block TCP/UDP/IP frag attacks
!
deny ip any any fragments
!
! Limit SNMP (should set source address to management stations)
! Must be tuned for SNMP walks. May need to adjust the SNMP client
! retry count or timeout.
!
permit udp any any eq snmp rate-limit 1024 128
!
! Allow other traffic types to come to CPU
!
permit every
exit
ip access-group reduce-dos-attacks control-plane
!
NOTE:
The rate limits below should be adjusted to match the expected rates of
traffic coming to the CPU.
Summary of Contents for N2000 Series
Page 50: ...50 Contents ...
Page 54: ...54 Introduction ...
Page 134: ...134 Using Dell OpenManage Switch Administrator ...
Page 168: ...168 Setting Basic Network Information ...
Page 206: ...206 Managing a Switch Stack ...
Page 242: ...242 Configuring Authentication Authorization and Accounting ...
Page 318: ...318 Managing General System Settings Figure 12 24 Verify MOTD ...
Page 322: ...322 Managing General System Settings ...
Page 358: ...358 Configuring SNMP ...
Page 388: ...388 Managing Images and Files ...
Page 415: ...Monitoring Switch Traffic 415 Figure 16 2 sFlow Agent Summary ...
Page 451: ...Monitoring Switch Traffic 451 5 On the Capture Options dialog click Manage Interfaces ...
Page 458: ...458 Monitoring Switch Traffic ...
Page 488: ...488 Configuring Port Characteristics Figure 18 3 Copy Port Settings 8 Click Apply ...
Page 502: ...502 Configuring Port Characteristics ...
Page 567: ...Configuring Port and System Security 567 Figure 19 38 Captive Portal Client Status ...
Page 674: ...674 Configuring VLANs Figure 21 17 GVRP Port Parameters Table ...
Page 680: ...680 Configuring VLANs Figure 21 24 Double VLAN Port Parameter Table ...
Page 714: ...714 Configuring VLANs ...
Page 737: ...Configuring the Spanning Tree Protocol 737 Figure 22 9 Spanning Tree Global Settings ...
Page 760: ...760 Configuring the Spanning Tree Protocol ...
Page 786: ...786 Discovering Network Devices ...
Page 793: ...Configuring Port Based Traffic Control 793 Figure 24 3 Storm Control 5 Click Apply ...
Page 878: ...878 Configuring Connectivity Fault Management ...
Page 899: ...Snooping and Inspecting Traffic 899 Figure 27 17 DAI Interface Configuration Summary ...
Page 903: ...Snooping and Inspecting Traffic 903 Figure 27 24 Dynamic ARP Inspection Statistics ...
Page 924: ...924 Configuring Link Aggregation Figure 28 7 LAG Hash Summary ...
Page 982: ...982 Configuring Link Aggregation ...
Page 1062: ...1062 Configuring DHCP Server and Relay Settings ...
Page 1096: ...1096 Configuring L2 and L3 Relay Features Figure 34 3 DHCP Relay Interface Summary ...
Page 1200: ...1200 Configuring OSPF and OSPFv3 ...
Page 1216: ...1216 Configuring RIP ...
Page 1240: ...1240 Configuring VRRP ...
Page 1291: ...Configuring Differentiated Services 1291 Figure 40 5 DiffServ Class Criteria ...
Page 1336: ...1336 Configuring Auto VoIP ...
Page 1367: ...Managing IPv4 and IPv6 Multicast 1367 Figure 43 20 IGMP Cache Information ...
Page 1422: ...1422 Managing IPv4 and IPv6 Multicast ...
Page 1440: ...1440 System Process Definitions ...
Page 1460: ...Index 1460 ...