Enabling/Disabling Ip Services - Alcatel-Lucent OmniSwitch AOS Release 7 Manual

Network configuration guide
Hide thumbs Also See for OmniSwitch AOS Release 7:
Table of Contents

Advertisement

-> ip dos scan threshold 2000
Setting the Decay Value
The decay value is the amount the total penalty value is divided by every minute. As the switch records
incoming UDP and TCP packets, it adds their assigned penalty values together to create the total penalty
value for the switch. To prevent the switch from registering a port scan from normal traffic, the decay
value is set to lower the total penalty value every minute to compensate from normal traffic flow.
To set the decay value, enter the decay value with the
the decay value to 2, enter the following:
-> ip dos scan decay 2
Enabling DoS Traps
DoS traps must be enabled in order for the switch to warn the administrator that a port scan can be in
progress when the total penalty value of the switch crosses the port scan penalty value threshold.
To enable SNMP trap generation, enter the
-> ip dos trap enable
To disable DoS traps, enter the same
-> ip dos trap disable
ARP Poisoning
ARP Poisoning allows an attacker to sniff and tamper the data frames on a network. It also modifies or
halts the traffic. The principle of ARP Poisoning is to send false or spoofed ARP messages to an Ethernet
LAN.
Alcatel-Lucent introduces the functionality that detects the presence of an ARP poisoning host on a
network. This functionality uses a configured restricted IP addresses, so that the switch does not get ARP
response on sending an ARP request. If an ARP response is received, then an event is logged and the user
is alerted using an SNMP trap.
Use the
arp filter
command to add an ARP Poison restricted address. Enter the command, followed by the
IP address. For example, to add an ARP Poison restricted address as 192.168.1.1, you would enter:
-> ip dos arp-poison restricted-address 192.168.1.1
To delete an ARP Poison restricted address, enter no ip dos arp-poison restricted-address followed by
the IP address. For example:
-> no ip dos arp-poison restricted-address 192.168.1.1
To verify the number of attacks detected for configured ARP poison restricted addresses, use the
dos arp-poison
command. For more information about this command, see the OmniSwitch CLI Reference
Guide.

Enabling/Disabling IP Services

When a switch initially boots up, all supported TCP/UDP well-known service ports are enabled (open).
Although these ports provide access for essential switch management services, such as telnet, ftp, snmp,
etc., they also are vulnerable to DoS attacks. It is possible to scan open service ports and launch such
attacks based on well-known port information.
OmniSwitch AOS Release 7 Network Configuration Guide
ip dos scan decay
ip dos trap
command, as shown:
ip dos trap
command, as shown:
March 2011
command. For example, to set
show ip
page 1127

Advertisement

Table of Contents
loading

This manual is also suitable for:

Omniswitch aos 7

Table of Contents