XGS-5240-Series User Manual

Table Of Contents
Configuration Guide of XGS-5240-Series
50-1
Chapter 50 Security Feature
Configuration
50.1 Introduction to Security Feature
Before introducing the security features, we here first introduce the DoS. The DoS
is short for Denial of Service, which is a simple but effective destructive attack on the i
nternet. The server under DoS attack will drop normal user data packet due to non-sto
p processing the attacker’s data packet, leading to the denial of the service and worse
can lead to leak of sensitive data of the server.
Security feature refers to applications such as protocol check which is for protectin
g the server from attacks such as DoS. The protocol check allows the user to drop ma
tched packets based on specified conditions. The security features provide several simp
le and effective protections against Dos attacks while acting no influence on the linear f
orwarding performance of the switch.
50.2 Security Feature Configuration
50.2.1
Prevent IP Spoofing Function Configuration Task Se
quence
1Enable the IP spoofing function.
Command
Explanation
Global Mode
[no] dosattack-check srcip-equal-dsti
p enable
Enable/disable the function of checking if th
e IP source address is the same as the de
stination address.
50.2.2 Prevent TCP Unauthorized Label Attack Function C
onfiguration Task Sequence
1Enable the anti TCP unauthorized label attack function
2Enable Checking IPv4 fragment function