User Manual

Table Of Contents
24-Port and 48-Port Gigabit Ethernet PoE+ Smart Switches with 4 SFP Ports
Configure System Information User Manual83
7. Select the types of DoS attacks for the switch to monitor and block and configure any
associated values:
Denial of Service Min TCP Header Size. Specify the minimum allowed
TCP header
size. If you select the Denial of Service
TCP Fragment Enable radio button, the
switch first drops packets for which the first TCP fragments include the following TCP
payload: IP_Payload_Length - IP_Header_Size <
Min_TCP_Header_Size. Enter a value in the range from 0 to 31. The default value
is 20.
Denial of Service Max ICMP Packet Size. Specify the maximum allowed ICMP
packet size. If you select the Denial of Service ICMPv4 Enable radio button or the
Denial of Service ICMPv6 Enable radio button, the switch drops ICMP or ICMPv6
ping packets that exceed the size that you specify
. Enter a value in the range from 0
to 16376.
The default value is 512.
Denial of Service ICMPv4. Enabling ICMPv4 DoS prevention causes the switch to
drop ICMPv4 packets with a type set to ECHO_REQ (ping) and a size that exceeds
the specified maximum allowed ICMP packet size. By default, this option is disabled.
Denial of Service ICMPv6. Enabling ICMPv6 DoS prevention causes the switch to
drop ICMPv6 packets with a type set to ECHO_REQ (ping) and a size that exceeds
the specified maximum allowed ICMPv6 packet size. By default, this option is
disabled.
Denial of Service Ping of death. Enabling Ping of Death DoS prevention causes the
switch to drop ICMP ping packet larger than 65535 bytes. By default, this option is
disabled.