Alteon Application Switch Operating System Application Guide
Advanced Denial of Service Protection
Document ID: RDWR-ALOS-V2900_AG1302
625
5. In the Security menu, configure a pattern group and name it something relevant and easy to
remember.
6. Add the defined patterns to the pattern group.
7. Configure a filter and its appropriate protocol in which the patterns are found. In this case, the
ICMP protocol should be specified.
8. Set the filter action to deny.
9. Set the ICMP message type. Ping of Death uses the ICMP message type echoreq.
10. Apply the pattern group you configured in
to the filter.
11. Enable pattern matching on the filter.
8
BINMATCH=014F, offset=2, depth=0, op=eq, cont 256
9
STRMATCH=/default.htm offset=44, depth=30, op=eq, cont 256
10
BINMATCH=0000, offset=6, depth=0, op=gt, cont 256
11
BINMATCH=4000, offset=6, depth=0, op=lt, cont 256
>> /cfg/security/pgroup 2/name
Current pattern group name:
Enter new pattern group name: pingofdeath
>> Pattern Match Group 2# add 10
>> Pattern Match Group 2# add 11
>> /cfg/slb/filt 190
>> Filter 190 # proto icmp
>> Filter 190 # action deny
Current action: none
Pending new action: deny
>> Filter 190 # adv/icmp
>> Filter 190 Advanced# icmp
Current ICMP message type: any
Enter ICMP message type or any: echoreq
>> Filter 190 # security/addgrp 2
Group ID 2 added.
>> /cfg/slb/filt 190/adv/security/pmatch enable
Current Pattern Match: disabled
New Pattern Match: enabled
ID
SLB String