User's Manual

Table Of Contents
Configuration Guide of XGS-5240-Series
50-2
Command
Explanation
Global Mode
[no] dosattack-check tcp-flags enable
Enable/disable checking TCP label function.
[no] dosattack-check ipv4-first-fragme
nt enable
Enable/disable checking IPv4 fragment. This
command has no effect when used separa
tely, but if this function is not enabled, the
switch will not drop the IPv4 fragment pack
et containing unauthorized TCP labels.
50.2.3 Anti Port Cheat Function Configuration Task Seque
nce
1 Enable the anti port cheat function
Command
Explanation
Global Mode
[no] dosattack-check srcport-equal-ds
tport enable
Enable/disable the prevent-port-cheat functio
n.
[no] dosattack-check ipv4-first-fragme
nt enable
Enable/disable checking IPv4 fragment. This
command has no effect when used separa
tely, but if this function is not enabled, the
switch will not drop the IPv4 fragment pack
et whose source port is equal to its destina
tion port.
50.2.4 Prevent TCP Fragment Attack Function Configuratio
n Task Sequence
1Enable the prevent TCP fragment attack function
2Configure the minimum permitted TCP head length of the packet
Command
Explanation
Global Mode
[no] dosattack-check tcp-fragment en
able
Enable/disable the prevent TCP fragment at
tack function.