ESR-Series. User manual
389
Command
Description
ip firewall screen suspicious-packets
large-icmp
The given command enables the blocking of ICMP packets more than 1024
bytes.
ip firewall screen suspicious-packets
syn-fragment
This command enables the blocking of fragmented TCP packets with the SYN
flag. TCP packets with the SYN flag are usually small and there is no need to
fragment them. The protection prevents concentration of fragmented packets in
a buffer.
ip firewall screen suspicious-packets
udp-fragment
The given command enables the blocking of fragmented UDP packets.
ip firewall screen suspicious-packets
unknown-protocols
The given command enables the blocking of packets, with the protocol ID
contained in IP header equal to 137 and more.
13.3.3 Configuration example of logging and protection against network attacks
Objective:
Protect LAN and ESR router from land, syn-flood, ICMP flood network attacks and configure the notification of
attacks by SNMP to SNMP server 192.168.0.10
Solution:
You should first configure interfaces and firewall (firewall configuration or its absence will not influence on the
operation of network attacks protection):
Содержание ESR Series
Страница 218: ...ESR Series User manual 218 ...
Страница 234: ...ESR Series User manual 234 In addition to RIP protocol configuration open UDP port 520 in the firewall ...
Страница 306: ...ESR Series User manual 306 Parameter targeted LDP Hold timer 45 seconds Keepalive holdtime 180 seconds ...
Страница 452: ...ESR Series User manual 452 Step Description Command Keys 4 Enable Tracking object esr config tracking enable ...
Страница 514: ...ESR Series User manual 514 esr show ntp peers ...