
After the maximum length of ICMP packets is set, you must enable the large ICMP packet attack
defense function; otherwise, the AR1200-S does not detect the attack packets or take attack
defense measures.
Step 11
Run:
firewall defend ping-of-death enable
The Ping of Death attack defense is enabled.
Step 12
Run:
firewall defend port-scan enable
The port scanning attack defense is enabled.
After the parameters for port scanning attack defense are set, you must enable the port scanning
attack defense function; otherwise, the AR1200-S does not detect the attack packets or take
attack defense measures.
Step 13
Run:
firewall defend smurf enable
The Smurf attack defense is enabled.
Step 14
Run:
firewall defend syn-flood enable
The SYN Flood attack defense is enabled.
After the parameters for SYN Flood attack defense are set, you must enable the SYN Flood
attack defense function; otherwise, the AR1200-S does not detect the attack packets or take
attack defense measures.
Step 15
Run:
firewall defend tcp-flag enable
The TCP flag attack defense is enabled.
Step 16
Run:
firewall defend teardrop enable
The Teardrop attack defense is enabled.
Step 17
Run:
firewall defend tracert enable
The Tracert attack defense is enabled.
Step 18
Run:
firewall defend udp-flood enable
The UDP Flood attack defense is enabled.
After the parameters for UDP Flood attack defense are set, you must enable the UDP Flood
attack defense function; otherwise, the AR1200-S does not detect the attack packets or take
attack defense measures.
Step 19
Run:
firewall defend winnuke enable
The WinNuke attack defense is enabled.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
3 Firewall Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
69