SNR S2940-8G-v2 Switch Configuration Guide
Security Feature Configuration
Chapter 48
Security Feature Configuration
48.1
Introduction to Security Feature
Before introducing the security features, we here first introduce the DoS. The DoS is short for
Denial of Service, which is a simple but effective destructive attack on the internet. The server
under DoS attack will drop normal user data packet due to non-stop processing the attacker’s
data packet, leading to the denial of the service and worse can lead to leak of sensitive data of the
server.
Security feature refers to applications such as protocol check which is for protecting the server
from attacks such as DoS. The protocol check allows the user to drop matched packets based
on specified conditions. The security features provide several simple and effective protections
against Dos attacks while acting no influence on the linear forwarding performance of the switch.
48.2
Security Feature Configuration
48.2.1
Prevent IP Spoofing Function Configuration Task Sequence
1. Enable the IP spoofing function.
Command
Explanation
Global mode
[no]
dosattack-check
srcip-
equal-dstip enable
Enable/disable the function of checking if the IP source ad-
dress is the same as the destination address.
48.2.2
Prevent TCP Unauthorized Label Attack Function Configuration Task
Sequence
1. Enable the anti TCP unauthorized label attack function
Command
Explanation
Global mode
[no] dosattack-check tcp-flags enable
Enable/disable checking TCP label function.
332
Summary of Contents for S2940-8G-v2
Page 11: ...SNR S2940 8G v2 Switch Configuration Guide Part I Basic Management Configuration 11...
Page 46: ...SNR S2940 8G v2 Switch Configuration Guide Part II Port Configuration 46...
Page 123: ...SNR S2940 8G v2 Switch Configuration Guide Part III VLAN and MAC Table Configuration 123...
Page 164: ...SNR S2940 8G v2 Switch Configuration Guide Part IV MSTP Configuration 164...
Page 198: ...SNR S2940 8G v2 Switch Configuration Guide Part VI L3 Forward and ARP Configuration 198...
Page 218: ...SNR S2940 8G v2 Switch Configuration Guide Part VII DHCP Configuration 218...
Page 257: ...SNR S2940 8G v2 Switch Configuration Guide Part VIII Multicast Protocol 257...
Page 278: ...SNR S2940 8G v2 Switch Configuration Guide Part IX Security Function Configuration 278...
Page 376: ...SNR S2940 8G v2 Switch Configuration Guide Part X Reliability Configuration 376...
Page 395: ...SNR S2940 8G v2 Switch Configuration Guide Part XI Flow Monitor Configuration 395...
Page 403: ...SNR S2940 8G v2 Switch Configuration Guide Part XII Network Time Management Configuration 403...
Page 411: ...SNR S2940 8G v2 Switch Configuration Guide Part XIII Debugging and Diagnosis 411...