Configuring Fragmented Packet Attack Defense - Huawei AR1200-S Configuration Manual

Enterprise routers
Hide thumbs Also See for AR1200-S:
Table of Contents

Advertisement

Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
<Huawei> display anti-attck statistics abnormal
Packets Statistic Information:
-------------------------------------------------------------------------------
AntiAtkType
-------------------------------------------------------------------------------
Abnormal
-------------------------------------------------------------------------------

14.3 Configuring Fragmented Packet Attack Defense

Fragmented packet attacks can be classified into attacks of a huge number of fragments, Tear
Drop, syndrop, nesta, fawx, bonk, NewTear, Bonk, Rose, huge-offset, Ping of death, Jolt, and
duplicated fragmentation.
14.3.1 Establishing the Configuration Task
This section describes the applicable environment, required tasks, and data for configuring
defense against fragmented packet attacks.
Applicable Environment
Different types of attacks on a network cause network devices overused, and even failed, thus
affecting network services.
To prevent the network devices from being attacked and to ensure normal network services,
defense against packet fragment attacks must be configured.
Pre-configuration Tasks
Before configuring defense against packet fragment attacks, complete the following tasks:
l
Data Preparation
To configure defense against packet fragment attacks, you need the following data:
No.
1
14.3.2 Configuring Defense Against Packet Fragment Attacks
The major measure to defend fragmented packet attacks is to limit the packet rate. In this manner,
you can prevent attackers from sending a great number of fragmented packets to cause a high
CPU usage and ensure that the CPU works normally when being attacked.
Context
Do as follows on the router:
Issue 02 (2012-03-30)
TotalPacketNum
(H)
(L)
0
Setting the link layer protocol parameters (and the IP address) for the interface to make the
status of link protocol Up
Data
Restricted rate of packet fragments
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
14 Configuration of Attack Defense and Application Layer
DropPacketNum
(H)
0
0
PassPacketNum
(L)
(H)
0
0
Association
(L)
0
285

Advertisement

Table of Contents
loading

Table of Contents