Ip-Zero-Length; Log; No All; No Attack - Alcatel-Lucent OmniAccess 700 CLI Command Reference Manual

Release versions: 2.2; 2.2-r02; 2.3
Table of Contents

Advertisement

Left running head:
Chapter name (automatic)
Filter and Firewall
-
-
IP
ZERO
LENGTH

ip-zero-length

D
ESCRIPTION
This attack is caused when the first fragment in the list is of 0-length. This sends a
series of IP fragments such that a 0 length fragment is first in the fragment list.
This makes it impossible for the kernel to deallocate the destination entry and
remove it from the cache. This leads to a system crash. This attack is prevented
by use of the above command.
P
ARAMETERS
None.
E
XAMPLE
ALU(config-firewall-attack-A1)# ip-zero-length

LOG

log
D
ESCRIPTION
Enter this command in the Firewall-Attack Sub Configuration mode. This
command logs all the attacks in the log server.
P
ARAMETERS
None.
E
XAMPLE
ALU(config-firewall-attack-A1)# log

NO ALL

no all
This command is entered in the Firewall-Attack Sub Configuration mode. The 'no'
command disables all the attacks configured for an attack object.

NO ATTACK

no attack <name>
This command is entered in the Firewall Configuration mode. This deletes the
specified DoS attack object and its configuration. You cannot delete an attack
object if it is attached to an interface.
614
Beta
Alcatel-Lucent
OmniAccess 700 CLI Command Reference Guide
Beta

Advertisement

Table of Contents
loading

Table of Contents