Instruction Manual
113
Viewing Port Security Status
•
On the
Port Security Status
page, the following information will be displayed:
•
Port Name:
Displays the port number the security is set up on.
•
Enable State:
Displays whether the port is
Enabled
or
Disabled
.
•
L2 Entry Num:
Displays the maximum number of MAC addresses that can
be on the corresponding port at one time.
•
Action:
Displays the action that will apply if the port exceeds the MAC
address limit either
Forwarded
,
Shutdown
, or
Discard
.
DoS
A Denial of Service (DoS) attack is a simple but destructive attack on the internet.
A server under DoS attack will drop normal user data packets due to non-stop
processing of the attacker’s data packet, leading to the denial of the service, and
worse can lead to leak of sensitive data of the server.
Security Feature
refers to applications such as protocol check which is for
protecting the server from attacks such as DoS. The protocol check allows
the user to drop matched packets based on specified conditions. The security
features provide several simple and effective protections against DoS attacks
while having no influence on the linear forwarding performance of the switch.
Applying Global DoS Settings
1.
On the
Global DoS Settings
page, select the DoS settings you want to apply:
•
DMAC = SMAC:
Allows you to enable or disable the DoS check mode for
DMAC = SMAC attacks.
•
Land:
Allows you to enable or disable the DoS check mode for Land attacks.
•
UDP Blat:
Allows you to enable or disable the DoS check mode for UDP Blat
attacks.
•
TCP Blat:
Allows you to enable or disable the DoS check mode for TCP Blat
attacks.
•
POD:
Allows you to enable or disable the DoS check mode for POD attacks.
•
IPv6 Min Fragment:
Allows you to enable or disable the DoS check mode
for IPv6 Min Fragment attacks and enter the minimum fragment value.
•
ICMP Fragments:
Allows you to enable or disable the DoS check mode for
ICMP Fragment attacks.