Dos-Control Firstfrag; Dos-Control Tcpfrag - NETGEAR M6100 Series Reference Manual

Hide thumbs Also See for M6100 Series:
Table of Contents

Advertisement

no dos-control sipdip
This command disables Source IP address = Destination IP address (SIP = DIP) Denial of
Service prevention.
Format
no dos-control sipdip
Mode
Global Config

dos-control firstfrag

This command enables Minimum TCP Header Size Denial of Service protection. If the mode
is enabled, Denial of Service prevention is active for this type of attack. If packets ingress
having a TCP Header Size smaller then the configured value, the packets will be dropped if
the mode is enabled. The default is disabled. The range is 0–255. If you enable dos-control
firstfrag, but do not provide a Minimum TCP Header Size, the system sets that value to 20.
Default
disabled (20)
Format
dos-control firstfrag [size]
Mode
Global Config
no dos-control firstfrag
This command sets Minimum TCP Header Size Denial of Service protection to the default
value of disabled.
Format
no dos-control firstfrag
Mode
Global Config

dos-control tcpfrag

This command enables TCP Fragment Denial of Service protection. If the mode is enabled,
Denial of Service prevention is active for this type of attack and packets that have a TCP
payload in which the IP payload length minus the IP header size is less than the minimum
allowed TCP header size are dropped.
Default
disabled
Format
dos-control tcpfrag
Mode
Global Config
M6100 Series Switches
Switching Commands
560

Advertisement

Table of Contents
loading

Table of Contents