Preventing Other Types Of Dos Attacks; Protocol-Based Rate Limiting - Radware Alteon Application Manual

Application switch operating system
Hide thumbs Also See for Alteon:
Table of Contents

Advertisement

To view the current values associated with these DoS attacks
Use of the of the following commands:
>> Main# /cfg/security/dos/cur
>> Main# /info/security/dos
To display a brief explanation of any of the DoS attacks that Alteon guards against
>> Main# /cfg/security/dos/help

Preventing Other Types of DoS Attacks

Table 52 describes how to prevent other types of DoS attacks.
DoS Attack
Description
Ping Flood
Flood of ICMP packets
intentionally sent to overwhelm
servers. The server is removed
from service while it attempts
to reply to every ping.
Ping of Death
A ping of death attack sends
fragmented ICMP echo request
packets. When these packets are
reassembled, they are larger
than the 65536 byte packets
allowed by the IP protocol.
Oversized packets cause
overflows in the server's input
buffer, and can cause a system
to crash, hang, or reboot.

Protocol-Based Rate Limiting

Alteon lets you detect and block certain kinds of protocol-based attacks. These attacks can flood
servers with enough traffic to severely affect their performance or bring them down altogether.
Protocol-based rate limiting is implemented via filters. Alteon currently supports rate limiting on TCP,
UDP, and ICMP protocols. Each filter is configured with one of the above protocols, and then rate
limiting is enabled or disabled in the Filtering Advanced menu.
TCP Rate Limiting—Limits new TCP connection requests or SYN packets. Alteon monitors the
rate of incoming TCP connection requests to a virtual IP address and limits the client requests
with a known set of IP addresses. For more information, see
Document ID: RDWR-ALOS-V2900_AG1302
Alteon Application Switch Operating System Application Guide
Table 52: DoS Attack Prevention Commands
Advanced Denial of Service Protection
User Action
4: A Rate Limiting Filter to
Configure
Thwart Ping Flooding, page 617
ICMP packets.
Configure FragOversize or
and Denying Large Packets—ICMP Ping of
Death Example, page 623
TCP Rate Limiting, page
to limit
Matching
.
613.
611

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents