Switching Commands
192
ProSafe Managed Switch
having a TCP Header Size smaller then the configured value, the packets will be dropped if
the mode is enabled.The default is
disabled.
If you enable dos-control firstfrag, but do not
provide a Minimum TCP Header Size, the system sets that value to
20
.
Default
Format
dos-control firstfrag
[<0-255>]
Mode
no dos-control firstfrag
This command sets Minimum TCP Header Size Denial of Service protection to the default
value of
disabled
.
Format
no dos-control firstfrag
Mode
dos-control tcpfrag
This command enables TCP Fragment Denial of Service protection. If the mode is enabled,
Denial of Service prevention is active for this type of attack. If packets ingress having IP
Fragment Offset equal to one (1), the packets will be dropped if the mode is enabled.
Default
Format
dos-control tcpfrag
Mode
no dos-control tcpfrag
This command disabled TCP Fragment Denial of Service protection.
Format
no dos-control tcpfrag
Mode
dos-control tcpflag
This command enables TCP Flag Denial of Service protections. If the mode is enabled,
Denial of Service prevention is active for this type of attacks. If packets ingress having TCP
Flag SYN set and a source port less than 1024 or having TCP Control Flags set to 0 and TCP
Sequence Number set to 0 or having TCP Flags FIN, URG, and PSH set and TCP Sequence
Number set to 0 or having TCP Flags SYN and FIN both set, the packets will be dropped if
the mode is enabled.
disabled <20>
Global Config
Global Config
disabled
Global Config
Global Config
Default
disabled