106
dosattack-check tcp-header <size>
dosattack-check tcp-fragment enable
Configure the minimum permitted TCP head
length of the packet. This command has no
effect when used separately, the user should
enable the
dosattack-check tcp-fragment
enable
2.6.2.5 Prevent ICMP Fragment Attack Function Configuration Task
Sequence
1
.
Enable the prevent ICMP fragment attack function
2
.
Configure the max permitted ICMPv4 net load length
3
.
Configure the max permitted ICMPv6 net load length
Command Explanation
Global Mode
dosattack-check icmp-attacking
enable
Enable the prevent ICMP fragment attack
function
dosattack-check icmpv4-size <size>
Configure the max permitted ICMPv4 net
length. This command has not effect when
used separately, the user have to enable the
dosattack-check icmp-attacking enable
dosattack-check icmpv6-size <size>
dosattack-check icmp-attacking enable
Configure the max permitted ICMPv6 net
length. This command has not effect when
used separately, the user have to enable the
dosattack-check icmp-attacking enable
2.6.3 Commands for Security Feature
2.6.3.1 dosattack-check srcip-equal-dstip enable
Command: [no] dosattack-check srcip-equal-dstip enable
Function:
Enable the function by which the switch checks if the source IP address is
equal to the destination IP address; the “no” form of this command disables this function.
Parameter:
None
Default:
Disable the function by which the switch checks if the source IP address is equal
to the destination IP address.