56
Gateway(config)# security
ddos icmp-smurf
Enable ICMP smurf function to prevent
the hacker to forge the IP address of the
Residential Gateway and send repeated
ping requests to it flooding the network.
Gateway(config)# security
ddos ip-land
Enable IP land function to prevent an
attack which involves a synchronized
request being sent as part of the three
way handshake of TCP to an open port
specifying the port as both the source and
destination effectively locking the port.
Gateway(config)# security
ddos ip-spoof
Enable IP spoof function to prevent a
hacker to create an alias IP address of the
Residential Gateway to which all traffic is
redirected.
Gateway(config)# security
ddos ip-teardrop
Enable to prevent a Teardrop attack. A
Teardrop attack sends mangled IP
fragments with overlapping, over-sized,
payloads to the Residential Gateway. The
fragmented packets are processed by the
Residential Gateway and will cause it to
crash.
Gateway(config)# security
ddos ping-of-death
Enable
to
prevent
the
Residential
Gateway to receive oversized ping
packets which it cannot handle. The Ping
of Death attack will send packets which
exceed the maximum IP packet size of
65,535 bytes.
Gateway(config)# security
ddos per-source-ip fin
Enable to prevent a FIN attack on the LAN
port IP address.
Gateway(config)# security
ddos per-source-ip fin [1-
999]
[1-999]
Specify the packets per second.
Gateway(config)# security
ddos per-source-ip icmp
Enable to prevent an ICMP attack on the
LAN port IP address.
Gateway(config)# security
ddos per-source-ip icmp [1-
999]
[1-999]
Specify the packets per second.
Gateway(config)# security
ddos per-source-ip syn
Enable to prevent a SYN attack on a
specified IP address.
Gateway(config)# security
ddos per-source-ip syn [1-
999]
[1-999]
Specify the packets per second.
Gateway(config)# security
ddos per-source-ip udp
Enable to prevent a UDP attack on the
LAN port IP address.
Gateway(config)# security
ddos per-source-ip udp [1-
999]
[1-999]
Specify the packets per second.
Gateway(config)# security
ddos source-ip-blocking
Enable to block the IP.
Gateway(config)# security
ddos source-ip-blocking [1-
999]
[1-999]
Specify the time in second to block the IP.