Denial of Service
Use the Denial of Service (DoS) page to configure DoS control. 200 Series software provides support
for classifying and blocking specific types of DoS attacks. You can configure your system to monitor
and block these types of attacks:
•
SIP=DIP: Source IP address = Destination IP address.
•
First Fragment: TCP Header size smaller then configured value.
•
TCP Fragment: IP Fragment Offset = 1.
•
TCP Flag: TCP Flag SYN set and Source Port < 1024 or TCP Control Flags = 0 and TCP Sequence
Number = 0 or TCP Flags FIN, URG, and PSH set and TCP Sequence Number = 0 or TCP Flags SYN
and FIN set.
•
L4 Port: Source TCP/UDP Port = Destination TCP/UDP Port.
•
ICMP: Limiting the size of
ICMP (Internet Control Message Protocol)
Ping packets.
To access this page, click
System
>
Advanced Configuration
>
Protection
>
Denial of Service
in the
navigation menu.
Table 48: Denial of Service Configuration Fields
Field
Description
TCP Settings
First Fragment
Enable this option to allow the device to drop packets that have a TCP header
smaller than the value configured in the Min TCP Hdr Size field.
TCP Port
Enable this option to allow the device to drop packets that have the TCP source
port equal to the TCP destination port.
UDP Port
Enable this option to allow the device to drop packets that have the UDP source
port equal to the UDP destination port.
SIP=DIP
Enable this option to allow the device to drop packets that have a source IP
address equal to the destination IP address.
SMAC=DMAC
Enable this option to allow the device to drop packets that have a source MAC
address equal to the destination MAC address.
TCP FIN and URG and PSH
Enable this option to allow the device to drop packets that have TCP Flags FIN,
URG, and PSH set and a TCP Sequence Number equal to 0.
TCP Flag and Sequence
Enable this option to allow the device to drop packets that have TCP control
flags set to 0 and the TCP sequence number set to 0.
TCP SYN
Enable this option to allow the device to drop packets that have TCP Flags SYN
set.
TCP SYN and FIN
Enable this option to allow the device to drop packets that have TCP Flags SYN
and FIN set.
TCP Fragment
Enable this option to allow the device to drop packets that have a TCP payload
where the IP payload length minus the IP header size is less than the minimum
allowed TCP header size.
TCP Offset
Enable this option to allow the device to drop packets that have a TCP header
Offset set to 1.
Configuring System Information
ExtremeSwitching 200 Series: Administration Guide
72