XGS-5240-Series User Manual

Table Of Contents
Configuration Guide of XGS-5240-Series
50-3
dosattack-check tcp-header <size>
Configure the minimum permitted TCP head
length of the packet. This command has n
o effect when used separately, the user sh
ould enable the dosattack-check tcp-fragm
ent enable.
50.2.5 Prevent ICMP Fragment Attack Function Configurati
on Task Sequence
1. Enable the prevent ICMP fragment attack function
2. Configure the max permitted ICMPv4 net load length
3. Configure the max permitted ICMPv6 net load length
Command
Explanation
Global Mode
[no] dosattack-check icmp-attacking
enable
Enable/disable the prevent ICMP fragment a
ttack function.
dosattack-check icmpv4-size <size>
Configure the max permitted ICMPv4 net lo
ad length. This command has not effect wh
en used separately, the user have to enabl
e the dosattack-check icmp-attacking ena
ble.
dosattack-check icmpv6-size <size>
Configure the max permitted ICMPv6 net lo
ad length. This command has not effect wh
en used separately, the user have to enabl
e the dosattack-check icmp-attacking ena
ble.
50.3 Security Feature Example
Scenario:
The User has follows configuration requirements: the switch do not forward data pa
cket whose source IP address is equal to the destination address, and those whose so
urce port is equal to the destination port. Only the ping command with defaulted option
s is allowed within the IPv4 network, namely the ICMP request packet can not be frag