Signature Detect - HP MSR Series Command Reference Manual

Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

signature detect

Use signature detect to configure signature detection for single-packet attacks.
Use undo signature detect to remove the signature detection configuration for single-packet attacks.
Syntax
signature detect { fraggle | fragment | impossible | ip-option-abnormal | land | large-icmp |
large-icmpv6 | ping-of-death | smurf | snork | tcp-all-flags | tcp-fin-only | tcp-invalid-flags |
tcp-null-flag | tcp-syn-fin | teardrop | tiny-fragment | traceroute | udp-bomb | winnuke } [ action
{ { drop | logging } * | none } ]
undo signature detect { fraggle | fragment | impossible | ip-option-abnormal | land | large-icmp |
large-icmpv6 | ping-of-death | smurf | snork | tcp-all-flags | tcp-fin-only | tcp-invalid-flags |
tcp-null-flag | tcp-syn-fin | teardrop | tiny-fragment | traceroute | udp-bomb | winnuke }
signature detect icmp-type { icmp-type-value | address-mask-reply | address-mask-request |
destination-unreachable | echo-reply | echo-request | information-reply | information-request |
parameter-problem
timestamp-request } [ action { { drop | logging } * | none } ]
undo signature detect icmp-type { icmp-type-value | address-mask-reply | address-mask-request |
destination-unreachable | echo-reply | echo-request | information-reply | information-request |
parameter-problem
timestamp-request }
signature detect icmpv6-type { icmpv6-type-value | destination-unreachable | echo-reply |
echo-request | group-query | group-reduction | group-report | packet-too-big | parameter-problem
| time-exceeded } [ action { { drop | logging } * | none } ]
undo signature detect icmpv6-type { icmpv6-type-value | destination-unreachable | echo-reply |
echo-request | group-query | group-reduction | group-report | packet-too-big | parameter-problem
| time-exceeded }
signature detect ip-option { option-code | internet-timestamp | loose-source-routing | record-route |
route-alert | security | stream-id | strict-source-routing } [ action { { drop | logging } * | none } ]
undo signature detect ip-option { option-code | internet-timestamp | loose-source-routing |
record-route | route-alert | security | stream-id | strict-source-routing }
signature detect ipv6-ext-header ext-header-value [ action { { drop | logging } * | none } ]
undo signature detect ipv6-ext-header next-header-value
Default
Signature detection is not configured for any single-packet attacks.
Views
Attack defense policy view
Predefined user roles
network-admin
Parameters
fraggle: Specifies the fraggle attack.
fragment: Specifies the fragment attack.
|
redirect
|
source-quench
|
redirect
|
source-quench
644
|
time-exceeded
|
|
time-exceeded
|
timestamp-reply
|
timestamp-reply
|

Advertisement

Table of Contents
loading

Table of Contents