Specifications

Table Of Contents
2-138
Cisco SCE 2000 and SCE 1000 CLI Command Reference
OL-26797-03
Chapter 2 CLI Command Reference
ip filter fragment
ip filter fragment
Use this command to enable the filtering out of IP fragments.
ip filter fragment enable
ip filter fragment disable
Syntax Description This command has no arguments or keywords.
Command Default By default, IP fragment filtering is disabled.
Command Modes Global configuration
Command History This table includes the following release-specific history entries:
Usage Guidelines Management security is defined as the capability of the SCE platform to cope with malicious
management conditions that might lead to global service failure.
There are two parallel security mechanisms:
Automatic security mechanism — monitors the TCP/IP stack rate at 200 msec intervals and throttles
the rate from the device if necessary.
User-configurable security mechanism — accomplished via two IP filters at user-configurable
intervals:
IP fragment filter: Drops all IP fragment packets
This command enables the IP fragment filter.
IP filter monitor: Measures the rate of accepted and dropped packets for both permitted and
not-permitted IP addresses.
Use the ip filter monitor command to configure the IP filter monitor.
Use the enable keyword to enable IP fragment filtering.
Use the disable keyword to disable IP fragment filtering.
Authorization: admin
Release Modification
3.0.0 This command was introduced.