Understanding How Dos Protection Works - Cisco WS-SUP32-GE-3B - Supervisor Engine 32 Software Configuration Manual

Software configuration guide
Hide thumbs Also See for WS-SUP32-GE-3B - Supervisor Engine 32:
Table of Contents

Advertisement

Understanding How DoS Protection Works

Understanding How DoS Protection Works
This section contains information about the available methods to counteract DoS attacks with a PFC3B
and includes configuration examples. The PFC3B provides a layered defense against DoS attacks using
the following methods:
These sections describe DoS protection with a PFC3B:
Security ACLs and VACLs
If the network is under a DoS attack, ACLs can be an efficient method for dropping the DoS packets
before they reach the intended target. Use security ACLs if an attack is detected from a particular host.
In this example, the host 10.1.1.10 and all traffic from that host is denied:
Router(config)# access-list 101 deny ip host 10.1.1.10 any
Catalyst Supervisor Engine 32 PISA Cisco IOS Software Configuration Guide, Release 12.2ZY
33-2
CPU rate limiters—Controls traffic types.
Control plane policing (CoPP)—Filters and rate limits control plane traffic. For information about
CoPP, see the
"Understanding How Control Plane Policing Works" section on page
Security ACLs and VACLs, page 33-2
QoS Rate Limiting, page 33-3
uRPF Check, page 33-3
Traffic Storm Control, page 33-4
Network Under SYN Attack, page 33-4
ARP Policing, page 33-5
Recommended Rate-Limiter Configuration, page 33-6
Hardware-Based Rate Limiters on the PFC3B, page 33-6
Ingress-Egress ACL Bridged Packets (Unicast Only), page 33-7
uRPF Check Failure, page 33-7
TTL Failure, page 33-8
ICMP Unreachable (Unicast Only), page 33-8
FIB (CEF) Receive Cases (Unicast Only), page 33-8
FIB Glean (Unicast Only), page 33-8
Layer 3 Security Features (Unicast Only), page 33-9
ICMP Redirect (Unicast Only), page 33-9
VACL Log (Unicast Only), page 33-9
MTU Failure, page 33-10
Layer 2 PDU, page 33-10
Layer 2 Protocol Tunneling, page 33-10
IP Errors, page 33-11
Layer 2 Multicast IGMP Snooping, page 33-10
IPv4 Multicast, page 33-11
IPv6 Multicast, page 33-11
Chapter 33
Configuring Denial of Service Protection
33-18.
OL-11439-03

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst supervisor engine 32 pisa

Table of Contents