
FL SWITCH GHS CLI
2-94
PHOENIX CONTACT
8039_en_01
D
ENIAL
OF
S
ERVICE
C
OMMANDS
This section describes the commands you use to configure Denial of Service (DoS) Control.
FL SWITCH GHS Firmware software provides support for classifying and blocking specific
types of Denial of Service attacks. You can configure your system to monitor and block six
types of attacks:
•
SIP=DIP:
Source IP address = Destination IP address.
•
First Fragment:
TCP Header size smaller then configured value.
•
TCP Fragment:
IP Fragment Offset = 1.
•
TCP Flag:
TCP Flag SYN set and Source Port < 1024 or TCP Control Flags = 0 and TCP
Sequence Number = 0 or TCP Flags FIN, URG, and PSH set and TCP Sequence
Number = 0 or TCP Flags SYN and FIN set.
•
L4 Port:
Source TCP/UDP Port = Destination TCP/UDP Port.
•
ICMP:
Limiting the size of ICMP Ping packets.
dos-control sipdip
This command enables Source IP address = Destination IP address (SIP=DIP) Denial of
Service protection. If the mode is enabled, Denial of Service prevention is active for this type
of attack. If packets ingress with SIP=DIP, the packets will be dropped if the mode is enabled.
no dos-control sipdip
This command disables Source IP address = Destination IP address (SIP=DIP) Denial of
Service prevention.
dos-control firstfrag
This command enables Minimum TCP Header Size Denial of Service protection. If the mode
is enabled, Denial of Service prevention is active for this type of attack. If packets ingress
having a TCP Header Size smaller then the configured value, the packets will be dropped if
Note:
Denial of Service (DataPlane) is not supported on the XGSII Tucana Platform. DoS is supported on XGSIII
platforms only.
Default
disabled
Format
dos-control sipdip
Mode
Global Config
Format
no dos-control sipdip
Mode
Global Config
RSPSupply - 1-888-532-2706 - www.RSPSupply.com
http://www.RSPSupply.com/p-14161-Phoenix-Contact-2700271-FL-SWITCH-GHS-4G/12-Modular-Ethernet-Switch.aspx