C
HAPTER
37
| Multicast Filtering Commands
IGMP Snooping
– 853 –
C
OMMAND
U
SAGE
As described in Section 9.1 of RFC 3376 for IGMP Version 3, the Router
Alert Option can be used to protect against DOS attacks. One common
method of attack is launched by an intruder who takes over the role of
querier, and starts overloading multicast hosts by sending a large number
of group-and-source-specific queries, each with a large source list and the
Maximum Response Time set to a large value.
To protect against this kind of attack, (1) routers should not forward
queries. This is easier to accomplish if the query carries the Router Alert
option. (2) Also, when the switch is acting in the role of a multicast host
(such as when using proxy routing), it should ignore version 2 or 3 queries
that do not contain the Router Alert option.
E
XAMPLE
Console(config)#ip igmp snooping router-alert-option-check
Console(config)#
ip igmp snooping
router-port-expire-
time
This command configures the querier time out. Use the
no
form to restore
the default.
S
YNTAX
ip igmp snooping router-port-expire-time
seconds
no ip igmp snooping router-port-expire-time
seconds
- The time the switch waits after the previous querier stops
before it considers it to have expired. (Range: 1-65535;
Recommended Range: 300-500)
D
EFAULT
S
ETTING
300 seconds
C
OMMAND
M
ODE
Global Configuration
E
XAMPLE
The following shows how to configure the time out to 400 seconds:
Console(config)#ip igmp snooping router-port-expire-time 400
Console(config)#
Summary of Contents for ES3510MA
Page 1: ...Management Guide www edge core com 8 Port Layer 2 Fast Ethernet Switch...
Page 4: ...ABOUT THIS GUIDE 4...
Page 30: ...CONTENTS 30...
Page 40: ...FIGURES 40...
Page 46: ...TABLES 46...
Page 48: ...SECTION I Getting Started 48...
Page 72: ...SECTION II Web Configuration 72...
Page 88: ...CHAPTER 3 Using the Web Interface Navigating the Web Browser Interface 88...
Page 116: ...CHAPTER 4 Basic Management Tasks Resetting the System 116...
Page 154: ...CHAPTER 5 Interface Configuration VLAN Trunking 154...
Page 216: ...CHAPTER 8 Spanning Tree Algorithm Configuring Interface Settings for MSTP 216...
Page 350: ...CHAPTER 14 Security Measures DHCP Snooping 350...
Page 440: ...CHAPTER 17 IP Services Displaying the DNS Cache 440...
Page 484: ...CHAPTER 19 Using the Command Line Interface CLI Command Groups 484...
Page 554: ...CHAPTER 21 System Management Commands Switch Clustering 554...
Page 574: ...CHAPTER 22 SNMP Commands 574...
Page 582: ...CHAPTER 23 Remote Monitoring Commands 582...
Page 636: ...CHAPTER 24 Authentication Commands Management IP Filter 636...
Page 736: ...CHAPTER 29 Port Mirroring Commands RSPAN Mirroring Commands 736...
Page 816: ...CHAPTER 34 VLAN Commands Configuring Voice VLANs 816...
Page 830: ...CHAPTER 35 Class of Service Commands Priority Commands Layer 3 and 4 830...
Page 848: ...CHAPTER 36 Quality of Service Commands 848...
Page 900: ...CHAPTER 38 LLDP Commands 900...
Page 910: ...CHAPTER 39 Domain Name Service Commands 910...
Page 916: ...CHAPTER 40 DHCP Commands DHCP Client 916...
Page 948: ...CHAPTER 41 IP Interface Commands IPv6 Interface 948...
Page 950: ...SECTION IV Appendices 950...
Page 982: ...INDEX 982...
Page 983: ......