Alteon Application Switch Operating System Application Guide
Advanced Denial of Service Protection
Document ID: RDWR-ALOS-V2900_AG1302
607
IPProt
An IPv4 packet with an unassigned
or reserved IP protocol.
Alteon checks for IPv4 packets with an
unassigned or reserved IP protocol, and
drops any matching packets.
IPOptLen
An IPv4 packet with an invalid IP
options length.
Alteon checks for IPv4 packets with an
invalid IP options length set, and drops any
matching packets.
FragMoreDont An IPv4 packet with the “more”
fragments and “don't” fragment bits
set.
Alteon checks for IPv4 packets with both the
“more” fragments and “don't” fragments bits
set, and drops any matching packets.
FragData
An IPv4 packet with the “more”
fragments bit set but a small
payload.
Alteon checks for IPv4 packets with the
“more” fragments bit set but exhibiting a
small payload, and drops any matching
packets.
FragBoundary An IPv4 packet with the “more”
fragments bit set but a payload not
at an 8-byte boundary.
Alteon checks for IPv4 packets with the more
fragments bit set but whose payload is not at
an 8-byte boundary, and drops any matching
packets.
FragLast
An IPv4 packet that is the last
fragment but no payload.
Alteon checks for IPv4 packets with the last
fragment bit set but no payload, and drops
any matching packets.
FragDontOff
An IPv4 packet with a non-zero
fragment offset and the “don't”
fragment bits set.
Alteon checks for IPv4 packets with a non-
zero fragment offset and the “don't”
fragment bits set, and drops any matching
packets.
FragOpt
An IPv4 packet with a non-zero
fragment offset and IP options bits
set.
Alteon checks for IPv4 packets with a non-
zero fragment offset and the IP options bits
set, and drops any matching packets.
FragOff
An IPv4 packet with a small non-
zero fragment offset.
Alteon checks for IPv4 packets with a small
non-zero fragment offset, and drops any
matching packets.
FragOverSize An IPv4 packet with a non-zero
fragment offset and an oversized
payload.
Alteon checks for IPv4 packets with a non-
zero fragment offset and an oversized
payload, and drops any matching packets.
TCPLen
A TCP packet with a TCP header
length less than 20 bytes and an IP
data length less than the TCP header
length.
Alteon checks for TCP packets with a TCP
header length less than 20 bytes and an IP
data length less than the TCP header length,
and drops any matching packets.
TCPPortZero
A TCP packet with a source or
destination port of zero.
Alteon checks for TCP packets with a source
or destination port of zero, and drops any
matching packets.
TCPReserved
A TCP packet with the TCP reserved
bit set.
Alteon checks for TCP packets with the TCP
reserved bit set, and drops any matching
packets.
NULLscan
A TCP packet with a sequence
number of zero or all of the control
bits are set to zero.
Alteon checks for TCP packets with a
sequence number or zero or with all control
bits set to zero, and drops any matching
packets.
Table 50: DoS Attacks Detected by Alteon
DoS Attack
Description
Action