Configuring Ip Virtual Fragment Reassembly; Configuration Guidelines; Configuration Procedure - HP 6125XLG Layer 3-Ip Services Configuration Manual

Blade switch
Table of Contents

Advertisement

To specify the source IP address for ICMP packets:
Step
1.
Enter system view.
2.
Specify the source address
for outgoing ICMP
packets.

Configuring IP virtual fragment reassembly

To make sure fragments arrive at a service module in order, the IP virtual fragment reassembly feature
virtually reassembles the fragments of a datagram through sequencing and caching. The IP virtual
fragment reassembly feature also prevents some service modules from processing packet fragments that
do not arrive in order.
For security purposes, the IP virtual fragment reassembly feature can detect the following types of
fragment attacks, and discard the attack fragments:
Tiny fragment attack—If the first fragment of an incoming datagram is smaller than the Layer 4
(such as TCP and UDP) header and the Layer 4 header is placed into the second fragment, a tiny
fragment attack occurs.
Overlapping fragment attack—If two consecutive incoming fragments are identical or overlap
each other, an overlapping fragment attack occurs.
Buffer overflow attack—If the number of concurrent reassemblies or the number of fragments per
datagram exceeds the upper limits, a buffer overflow attack occurs.

Configuration guidelines

When you configure IP virtual fragment reassembly, follow these guidelines:
The IP virtual fragment reassembly feature only applies to incoming packets on an interface.
The IP virtual fragment reassembly feature does not support load sharing. The fragments of an IP
datagram cannot arrive through different interfaces.

Configuration procedure

To configure IP virtual fragment reassembly:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Enable IP virtual fragment
reassembly.
Command
system-view
ip icmp source [ vpn-instance
vpn-instance-name ] ip-address
Command
system-view
interface interface-type interface-number
ip virtual-reassembly [ drop-fragments |
max-fragments number | max-reassemblies
number | timeout seconds ] *
127
Remarks
N/A
By default, the device uses the IP address
of the sending interface as the source IP
address for outgoing ICMP packets.
Remarks
N/A
N/A
By default, the feature is
disabled.

Advertisement

Table of Contents
loading

Table of Contents