Draytek Vigor2620 LTE Series User Manual page 439

Hide thumbs Also See for Vigor2620 LTE Series:
Table of Contents

Advertisement

T
e
l
n
e
t
C
o
m
m
T
e
l
n
e
t
C
o
m
m
This command allows users to configure the settings for DoS defense system.
S
S
y
y
n
n
t
t
a
a
x
x
dos <-V / D / A>
dos -s <ATTACK_F> <THRESHOLD> <TIMEOUT>
dos <-a /-e> <ATTACK_F><ATTACK_0>
dos -d <ATTACK_F><ATTACK_0>
dos -o <LOG_TYPE> -p<LOG_TYPE> -l <LOG_TYPE>
dos <-P/-B> add4 <ipv4_addr>
dos <-P/-B> remove4 <ipv4_addr/all>
dos <-P/-B> add6 <ipv6_addr>
dos <-P/-B> remove6 <ipv6_addr/all>
dos <-P/-B> show
S
y
n
t
a
x
S
y
n
t
a
x
Parameter
-V
-D
-A
-s
<ATTACK_F>
<THRESHOLD> <TIMEOUT>
-a
<ATTACK_F> <ATTACK_0>
-e
<ATTACK_F> <ATTACK_0>
-d
<ATTACK_F> <ATTACK_0>
Vigor2620 Series User's Guide
a
n
d
:
d
o
s
a
n
d
:
d
o
s
D
e
s
c
r
i
p
t
i
o
n
D
e
s
c
r
i
p
t
i
o
n
Description
It means to view the configuration of DoS defense system.
It means to deactivate the DoS defense system.
It means to activate the DoS defense system.
It means to enable the defense function for a specific attack
and set its parameter(s).
<ATTACK_F>: Specify the name of flooding attack(s) or
portscan, e.g., synflood, udpflood, icmpflood, or postscan.
<THRESHOLD>: It means the packet rate (packet/second)
that a flooding attack will be detected. Set a value larger
than 20.
<TIMEOUT>: It means the time (seconds) that a flooding
attack will be blocked. Set a value larger than 5.
It means to enable the defense function for all attacks listed
in ATTACK_0.
<ATTACK_F>: Specify the name of flooding attack(s) or
portscan, e.g., synflood, udpflood, icmpflood, or postscan.
< ATTACK_0>: Specify a name of the following attacks:
ip_option, tcp_flag, land, teardrop, smurf, pingofdeath,
traceroute, icmp_frag, syn_frag, unknow_proto, fraggle.
It means to enable defense function for a specific attack(s).
<ATTACK_F>: Specify the name of flooding attack(s) or
portscan, e.g., synflood, udpflood, icmpflood, or postscan.
< ATTACK_0>: Specify a name of the following attacks:
ip_option, tcp_flag, land, teardrop, smurf, pingofdeath,
traceroute, icmp_frag, syn_frag, unknow_proto, fraggle.
It means to disable the defense function for a specific
attack(s).
<ATTACK_F>: Specify the name of flooding attack(s) or
portscan, e.g., synflood, udpflood, icmpflood, or postscan.
< ATTACK_0>: Specify a name of the following attacks:
427

Advertisement

Table of Contents
loading

This manual is also suitable for:

Vigor2620lnVigor2620lne

Table of Contents