Configuring Tcp Fragment Attack Protection; Displaying And Maintaining Tcp Attack Protection - HP 3600 v2 Series Configuration Manual

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

Configuring TCP fragment attack protection

The TCP fragment attack protection feature enables the device to drop attack TCP fragments to prevent
TCP fragment attacks that packet filter cannot detect. As defined in RFC 1858, attack TCP fragments refer
to the following TCP fragments:
First fragments in which the TCP header is smaller than 20 bytes.
Non-first fragments with a fragment offset of 8 bytes (FO=1).
To configure TCP fragment attack protection:
Step
1.
Enter system view.
2.
Enable TCP fragment attack
protection.

Displaying and maintaining TCP attack protection

Task
Display current TCP connection state.
Command
system-view
attack-defense tcp fragment
enable
Command
display tcp status [ | { begin | exclude |
include } regular-expression ]
353
Remarks
N/A
By default, TCP fragment attack
protection is enabled.
Remarks
Available in any view

Advertisement

Table of Contents
loading

Table of Contents