SGS-6341-Series User Manual

Table Of Contents
dosattack-check icmpv4-size <size>
Configure the max. permitted ICMPv4 net load
length. This command has not effect when
used separately, the user have to enable the
dosattack-check icmp-attacking enable.
45.3 Security Feature Example
Scenario:
The User has the following configuration requirements: the switch do not forward data packet
whose source IP address is equal to the destination address, and those whose source port is
equal to the destination port. Only the ping command with defaulted options is allowed within
the IPv4 network, namely the ICMP request packet can not be fragmented and its net length is
normally smaller than 100.
Configuration procedure:
Switch(config)# dosattack-check srcip-equal-dstip enable
Switch(config)# dosattack-check srcport-equal-dstport enable
Switch(config)# dosattack-check icmp-attacking enable
Switch(config)# dosattack-check icmpV4-size 100
45-105
User’s Manual of SGS-6341 series