Optional Attacks - Alcatel-Lucent OmniAccess 700 Cli Configuration Manual

Release versions: 2.2, 2.2-r02, 2.3
Hide thumbs Also See for OmniAccess 700:
Table of Contents

Advertisement

O
A
PTIONAL
TTACKS
The following four DoS attacks are not set for prevention by default. These attacks
too can be either manually turned on for detection or filters can be applied to block
them.
-
-
-
ICMP
BLOCK
TRACE
ROUTE
icmp-block-trace-route
This command is not a default DoS setting. The square brackets around the
whole command denotes its only optional. This means that this attack is not set
for protection by default in the OA-700, but you can turn it on by explicitly adding
the above keyword in the user-defined attack prevention list.
-
-
ICMP
ROUTER
ADVERTISEMENT
icmp-router-advertisement
Remote attackers can spoof these ICMP packets and remotely add bad default-
route entries into a victims routing table. Since the victim's system would be
forwarding the frames to the wrong address, it will be unable to reach other
networks. This attack can be prevented by adding this command in the DoS
prevention list.
-
ICMP
REDIRECT
icmp-redirect
This command is not a default DoS setting. The square brackets around the
whole command denotes its only optional. However the above command can be
included in the DoS prevention list to avoid this kind of attacks.
-
-
IP
SOURCE
ROUTING
ip-source-routing
Source routing is a technique whereby the sender of a packet can specify the
route that a packet should take through the network. Attackers can use source
routing to probe the network by forcing packets into specific parts of the network.
Using source routing, an attacker can collect information about a networks
topology, or other information that could be useful in performing an attack. During
an attack, an attacker could use source routing to direct packets to bypass
existing security restrictions. This command is included in the default attack
protection list to secure the network from this attack.
CLI Configuration Guide
Beta
Except on the first page, right running head:
Heading1 or Heading1NewPage text (automatic)
Alcatel-Lucent
Network Attacks - An Overview
673
Beta

Advertisement

Table of Contents
loading

Table of Contents