109
Switch(Config)# dosattack-check tcp-header 20
2.6.3.7 dosattack-check icmp-attacking enable
Command: [no] dosattack-check icmp-attacking enable
Function:
Enable the ICMP fragment attack checking function on the switch; the “no”
form of this command disables this function
Parameter:
None
Default:
Disable the ICMP fragment attack checking function on the switch
Command Mode:
Global Mode
Usage Guide:
With this function enabled the switch will be protected from the ICMP
fragment attacks, dropping the fragment ICMPv4/v6 data packets whose net length is
smaller than the specified value
Example:
Enable the ICMP fragment attack checking function
Switch(Config)# dosattack-check icmp-attacking enable
2.6.3.8 dosattack-check icmpv4-size
Command: dosattack-check icmpv4-size <size>
Function:
Configure the max net length of the ICMPv4 data packet permitted by the
switch
Parameter:
<size> is the max net length of the ICMPv4 data packet permitted by the
switch
Default:
The value is 0x200 by default
Command Mode:
Global Mode
Usage Guide:
To use this function you have to enable “dosattack-check icmp-attacking
enable” first
Example:
Set the max net length of the ICMPv4 data packet permitted by the switch to
100
Switch(Config)# dosattack-check icmp-attacking enable
Switch(Config)# dosattack-check icmpv4-size 100
2.6.3.9 dosattack-check icmpv6-size
Command:dosattack-check icmpv6-size <size>
Function:
Configure the max net length of the ICMPv6 data packet permitted by the
switch
Parameter:
<size> is the max net length of the ICMPv6 data packet permitted by the
switch
Default:
The value is 0x200 by default
Command Mode:
Global Mode