DGS-1210 Metro Ethernet Managed Switch CLI Reference Guide
58
11
DOS PREVENTION COMMANDS
The DoS Prevention commands in the Command Line Interface (CLI) are listed (along with the appropriate
parameters) in the following table.
Command
Parameter
config dos_prevention
dos_type
[ {land_attack | blat_attack | smurf_attack | tcp_null_scan | tcp_xmascan |
tcp_synfin | tcp_syn_srcport_less_1024} | all] {action drop} | state [enable |
disable] ] }
show dos_prevention
{ land_attack | blat_attack | smurf_attack | tcp_null_scan | tcp_xmascan |
tcp_synfin | tcp_syn_srcport_less_1024 }
enable dos_prevention
trap_log
disable dos_prevention
trap_log
Each command is listed in detail, as follows:
config dos_prevention dos_type
Purpose
Used to discard the L3 control packets sent to CPU from specific
ports.
Syntax
config dos_prevention dos_type [ {land_attack | blat_attack |
smurf_attack | tcp_null_scan | tcp_xmascan | tcp_synfin |
tcp_syn_srcport_less_1024} | all] {action drop} | state [enable |
disable] ] }
Description
The
config dos_prevention dos_type
command is used to
configure the prevention of DoS attacks, and incluDGS state and
action. The packets matching will be used by the hardware. For a
specific type of attack, the content of the packet, regardless of the
receipt port or destination port, will be matched against a specific
pattern.
Parameters
The type of DoS attack. Possible values are as follows:
land_attack, blat_attack, smurf_attack, tcp_null_scan, tcp_xmascan
tcp_synfin and tcp_syn_srcport_less_1024.
By default, prevention for all types of DoS are enabled except for
tcp_syn_srcport_less_1024.
action [drop | mirror] -
When enabling DoS prevention, the following
actions can be taken.
drop –
Drop the attack packets.
mirror –
Mirror the packet to other port for further process.
priority <value (0-7)> –
Change packet priority by the Switch from 0
to 7.
If the priority is not specified, the original priority will be used.
rx_rate [no_limit | <value (64-1024000)>] –
controls the rate of the
received DoS attack packets. If not specified, the default action is
Содержание DGS-1210/ME series
Страница 61: ...DGS 1210 ME Metro Ethernet Switch CLI Reference Guide 41 Sending mail please wait Success DGS 1210 28MP ME 5 ...
Страница 186: ...DGS 1210 Metro Ethernet Managed Switch CLI Reference Guide 166 DGS 1210 28MP ME 5 ...
Страница 190: ...DGS 1210 Metro Ethernet Managed Switch CLI Reference Guide 170 Success DGS 1210 28MP ME 5 ...
Страница 386: ...DGS 1210 Metro Ethernet Managed Switch CLI Reference Guide 366 Port Max Group 1 v6 256 3 v6 256 DGS 1210 28MP ME 5 ...