HP 1820 Management And Configuration Manual page 84

Table of Contents

Advertisement

Security
Advanced Security Configuration
Figure 9-1. Advanced Security Configuration Page
Table 9-1. Advanced Security Configuration Fields
Field
Storm Control Features
Storm Control
Auto Dos Features
Auto DoS
Prevent Land
Attack
Prevent TCP
Blat Attack
Prevent UDP
Blat Attack
Prevent Invalid
TCP Flags
Attack
9-2
Description
Storm control enables the rate-limiting of incoming unicast (with unknown destination), multicast,
and broadcast traffic to prevent unnecessary congestion in the network. When enabled, the storm
control threshold is automatically set to 5% of port speed. If the incoming rate of unicast (with
unknown destination), multicast, or broadcast packets exceeds this value, the port discards the excess
traffic until the rate for that particular packet type falls below the threshold.
Note: The threshold percentage is translated to a packets-per-second value that is used by the switch
hardware to rate-limit the incoming traffic. This translation assumes a nominal 512 byte packet size
to determine the packets-per-second threshold based on the port speed. For example, the 5% threshold
applied to a 1 Gbps port equates to approximately 11748 packets-per-second, regardless of the actual
packet sizes being received by the port. Each of the three storm control packet types is rate-limited
independently.
Enable this option to enable all the DoS prevention mechanisms with default values. Enabling this
feature makes all the fields in the remainder of the table inaccessible (grayed-out). When disabled,
you can individually turn on and off the DoS features and change their default values. This feature
and all the individual DoS protections are disabled by default.
Enable this option to drop packets for which the source IP address equals the destination IP address.
Enable this option to drop packets for which the TCP source port equals the TCP destination port.
Enable this option to drop packets that have a UDP source port equal to the UDP destination port.
Enable this option to drop packets that have TCP Flags SYN and FIN set.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents