146
C
HAPTER
9: Q
O
S C
OMMANDS
Command Mode
Global Configuration mode
User Guidelines
The following table describes a list of DoS attacks and the protection
type:
Example
The following example protects the system from the Invasor Trojan.
security-suite deny
martian-addresses
The
security-suite deny martian-addresses
Global Configuration
mode command denies packets containing reserved IP addresses. Use the
no
form of this command to permit those addresses.
Syntax
s
ecurity-suite deny martian-addresses
{
reserved
|
add
{
ip-address
{
mask
|
prefix-length
}} |
remove
{i
p-address {mask | prefix-length
}}
no security-suite deny martian-addresses
Parameters
■
ip-address
— Specify the packets to discard, with that IP address as
the source IP address or the destination IP address.
■
mask
— Specifies the network mask of the IP address.
■
prefix-length
— Specifies the number of bits that comprise the IP
address prefix. The prefix length must be preceded by a forward slash
(/).
Attack
Keyword
Protection
Stacheldraht
Distribution DoS attack
stacheldraht
Discard TCP packets with source TCP
port equal to 16660.
Invasor Trojan
invasor-trojan
Discard TCP packets with destination
TCP port equal to 2140 and source
TCP port equal to 1024.
Back Orifice Trojan
back-orifice-tr
ojan
Discard UDP packets with destination
UDP port equal to 31337 and source
UDP port equal to 1024.
Console(config)#
security-suite dos protect add
invasor-trojan
Содержание 3CRUS2475 24
Страница 18: ......
Страница 40: ...40 CHAPTER 2 AAA COMMANDS ...
Страница 54: ...54 CHAPTER 3 ACL COMMANDS ...
Страница 76: ...76 CHAPTER 4 ADDRESS TABLE COMMANDS ...
Страница 165: ...show sntp status 165 g13 0 0 0 0 00 00 00 0 Feb 19 2005 vlan 1 16 1 1 2 00 15 15 16 0 LLBG Feb 19 2006 ...
Страница 166: ...166 CHAPTER 10 CLOCK COMMANDS ...
Страница 200: ...200 CHAPTER 13 LACP COMMANDS ...
Страница 208: ...208 CHAPTER 14 POWER OVER ETHERNET COMMANDS ...
Страница 262: ...262 CHAPTER 15 SPANNING TREE COMMANDS ...
Страница 278: ...278 CHAPTER 17 RADIUS COMMAND ...
Страница 281: ...show ports monitor 281 g1 8 RX TX Active g2 8 RX TX Active g18 8 RX Active ...
Страница 282: ...282 CHAPTER 18 PORT MONITOR COMMANDS ...
Страница 306: ...306 CHAPTER 19 SNMP COMMANDS ...
Страница 316: ...316 CHAPTER 20 IP ADDRESS COMMANDS ...
Страница 330: ...330 CHAPTER 22 WIRELESS ROGUE AP COMMANDS ...
Страница 350: ...350 CHAPTER 23 WIRELESS ESS COMMANDS ...
Страница 382: ...382 CHAPTER 25 SSH COMMANDS ...
Страница 400: ...400 CHAPTER 27 TACACS COMMANDS Global values TimeOut 3 ...
Страница 444: ...444 CHAPTER 31 USER INTERFACE COMMANDS ...
Страница 454: ...454 CHAPTER 32 GVRP COMMANDS ...
Страница 492: ...492 CHAPTER 34 802 1X COMMANDS ...
Страница 521: ...Troubleshooting Solutions 521 ...
Страница 522: ...522 CHAPTER 37 TROUBLESHOOTING ...