9-2
ges to TIME_WAIT. If
non-FIN
re received, the sy
r from receiving th
FIN packet.
roken after the timer expires.
Size of TCP receive/send buffer
F
CP
terminated. If FIN packets are received, the TCP connection state chan
packets a
stem restarts the time
e last non-
The connection is b
ollow these steps to configure T
attributes:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Configure T
timeout valu
CP synwait timer’s
e
tcp timer syn-timeout time-value
Optional
75 seconds by default.
Configure TCP finwait timer’s
Optional
timeout value
tcp timer fin-timeout time-value
675 seconds by default.
Configure the size of TCP
receive/send buffer
Optional
tcp window window-size
8 kilobytes by default.
Disabling ICMP to Send Error Packets
Sending error packets is a major function of ICMP protocol. In case of network abnormalities, ICMP
packets are usu
by the network or transport
tify correspondi
so
a
agement
Although sending ICMP error packets facilitate control and management, it still has the following
d
Sending a lot of ICMP packets will increase network traffic.
licious pac
send ICMP error packets, the device’s
performance will be reduced.
n function in
ble size of a host, the host’s performance
will be reduced if its routing table becomes very large.
s ICMP destinat
ckets, end users may be affected.
Y
ng network traffic and
p
alicious attacks.
F
IC
ckets:
ally sent
layer protocols to no
ng devices
s to facilitate control and man
.
isadvantages:
If receiving a lot of ma
kets that cause it to
As the ICMP redirectio
creases the routing ta
If a host sends maliciou
ion unreachable pa
ou can disable the device from send
reventing m
ing such ICMP error packets for reduci
ollow these steps to disable sending
MP error pa
To do…
Use the command…
Remarks
Enter system view
system-view
—
Disable sending ICMP redirects
undo icmp redirect send
Required
Enabled by default.
Disable sending ICMP destination
unreachable packets
undo icmp unreach send
Enab
Required
led by default.
Cance
m-Defined ACLs
I
ttacks are common in netwo
st malicious ICMP attacks, the device
p
to match the
ackets and process them
thus
red
pact on normal
asing network stabilit
ling the Syste
for ICMP Attack Guard
CMP a
rks. To guard again
re-defines some ACLs
incoming ICMP p
separately,
y.
ucing ICMP attacks’ im
data packets and incre