585
signature
detect
{
ip-option-abnormal
|
ping-of-death
|
teardrop
}
action
{
drop
|
logging
} *
undo signature
detect
{
ip-option-abnormal
|
ping-of-death
|
teardrop
}
signature detect
icmp-type
{
icmp-type-value
|
address-mask-reply
|
address-mask-request
|
destination-unreachable
|
echo-reply
|
echo-request
|
information-reply
|
information-request
|
parameter-problem
|
redirect
|
source-quench
|
time-exceeded
|
timestamp-reply
|
timestamp-request
} [
action
{ {
drop
|
logging
} *
|
none
} ]
undo signature detect
icmp-type
{
icmp-type-value
|
address-mask-reply
|
address-mask-request
|
destination-unreachable
|
echo-reply
|
echo-request
|
information-reply
|
information-request
|
parameter-problem
|
redirect
|
source-quench
|
time-exceeded
|
timestamp-reply
|
timestamp-request
}
signature detect
icmpv6-type
{
icmpv6-type-value
|
destination-unreachable
|
echo-reply
|
echo-request
|
group-query
|
group-reduction
|
group-report
|
packet-too-big
|
parameter-problem
|
time-exceeded
} [
action
{ {
drop
|
logging
} *
|
none
} ]
undo signature detect
icmpv6-type
{
icmpv6-type-value
|
destination-unreachable
|
echo-reply
|
echo-request
|
group-query
|
group-reduction
|
group-report
|
packet-too-big
|
parameter-problem
|
time-exceeded
}
signature detect
ip-option
{
option-code
|
internet-timestamp
|
loose-source-routing
|
record-route
|
route-alert
|
security
|
stream-id
|
strict-source-routing
} [
action
{ {
drop
|
logging
} *
|
none
} ]
undo signature detect
ip-option
{
option-code
|
internet-timestamp
|
loose-source-routing
|
record-route
|
route-alert
|
security
|
stream-id
|
strict-source-routing
}
signature detect ipv6-ext-header
ext-header-value
[
action
{ {
drop
|
logging
} *
|
none
} ]
undo signature detect ipv6-ext-header
next-header-value
Default
Signature detection is disabled for all single-packet attacks.
Views
Attack defense policy view
Predefined user roles
network-admin
mdc-admin
Parameters
fraggle
: Specifies the fraggle attack.
fragment
: Specifies the IP fragment attack.
icmp-type
: Specifies an ICMP packet attack by the packet type. You can specify the packet type by
a number or a keyword:
•
icmp-type-value
: Specifies the ICMP packet type in the range of 0 to 255.
•
address-mask-reply
: Specifies the ICMP address mask reply type.
•
address-mask-request
: Specifies the ICMP address mask request type.
•
destination-unreachable
: Specifies the ICMP destination unreachable type.
•
echo-reply
: Specifies the ICMP echo reply type.
•
echo-request
: Specifies the ICMP echo request type.
•
information-reply
: Specifies the ICMP information reply type.
•
information-request
: Specifies the ICMP information request type.
•
parameter-problem
: Specifies the ICMP parameter problem type.
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...