Switching Commands
191
ProSafe Managed Switch
•
TCP SYN:
TCP Flag SYN set.
•
TCP SYN & FIN:
TCP Flags SYN and FIN set.
•
TCP FIN & URG & PSH:
TCP Flags FIN and URG and PSH set and TCP Sequence
Number = 0.
•
ICMP V6:
Limiting the size of ICMPv6 Ping packets.
•
ICMP Fragment:
Checks for fragmented ICMP packets.
dos-control all
This command enables Denial of Service protection checks globally.
Default
Format
dos-control all
Mode
no dos-control all
This command disables Denial of Service prevention checks globally.
Format
no dos-control all
Mode
dos-control sipdip
This command enables Source IP address = Destination IP address (SIP=DIP) Denial of
Service protection. If the mode is enabled, Denial of Service prevention is active for this type
of attack. If packets ingress with SIP=DIP, the packets will be dropped if the mode is enabled.
Default
Format
dos-control sipdip
Mode
no dos-control sipdip
This command disables Source IP address = Destination IP address (SIP=DIP) Denial of
Service prevention.
Format
no dos-control sipdip
Mode
dos-control firstfrag
This command enables Minimum TCP Header Size Denial of Service protection. If the mode
is enabled, Denial of Service prevention is active for this type of attack. If packets ingress
disabled
Global Config
Global Config
disabled
Global Config
Global Config