SROS Command Line Interface Reference Guide
Global Configuration Mode Command Set
5991-2114
© Copyright 2007 Hewlett-Packard Development Company, L.P.
406
ip firewall check winnuke
Use the
ip firewall check winnuke
command to enable the SROS stateful inspection firewall to discard all
Out of Band (OOB) data (to protect against WinNuke attacks). Use the
no
form of this command to disable
this feature.
Syntax Description
No subcommands.
Default Values
All SROS security features are disabled by default until the
ip firewall
command is issued at the Global
Configuration prompt. Issuing the
ip firewall
command enables the WinNuke check.
Functional Notes
WinNuke attack is a well-known denial of service attack on hosts running Microsoft Windows
®
operating
systems. An intruder sends Out of Band (OOB) data over an established connection to a Windows user.
Windows cannot properly handle the OOB data and the host reacts unpredictably. Normal shut-down of the
hosts will generally return all functionality. Using the
ip firewall check winnuke
command configures the
SROS stateful inspection firewall to filter all OOB data to prevent network problems.
Usage Examples
The following example enables the firewall to filter all OOB data:
ProCurve(config)#
ip firewall check winnuke
Note
The SROS security features must be enabled (using the
ip firewall
command) for the
stateful inspection firewall to be activated.