Ip Fragment Reassembly; Overview; Configuring Ip Fragment Reassembly Parameters; Configuring The Method For Ip Fragment Reassembly - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Configuring Signatures

IP Fragment Reassembly

This section describes IP fragment reassembly, and contains the following topics:

Overview

You can configure the sensor to reassemble a datagram that has been fragmented over multiple packets.
You can specify boundaries that the sensor uses to determine how many datagrams and how long to wait
for more fragments of a datagram. The goal is to ensure that the sensor does not allocate all its resources
to datagrams that cannot be completely reassembled, either because the sensor missed some frame
transmissions or because an attack has been launched that is based on generating random fragmented
datagrams.
You configure the IP fragment reassembly per signature.

Configuring IP Fragment Reassembly Parameters

Table 7-5
fragment reassembly. The IP fragment reassembly signatures are part of the NORMALIZER engine.
Table 7-5
IP Fragment Reassembly Signature
1200 IP Fragmentation Buffer Full
1201 IP Fragment Overlap
1202 IP Fragment Overrun - Datagram Too Long
1203 IP Fragment Overwrite - Data is Overwritten
1204 IP Fragment Missing Initial Fragment
1205 IP Fragment Too Many Datagrams
1206 IP Fragment Too Small
1207 IP Fragment Too Many Datagrams
1208 IP Fragment Incomplete Datagram
1220 Jolt2 Fragment Reassembly DoS attack
1225 Fragment Flags Invalid
To configure IP fragment reassembly parameters, follow these steps:
Log in to the CLI using an account with administrator or operator privileges.
Step 1
Enter signature definition submode:
Step 2
sensor# configure terminal
sensor(config)# service signature-definition sig0
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
7-22
Overview, page 7-22
Configuring IP Fragment Reassembly Parameters, page 7-22
Configuring the Method for IP Fragment Reassembly, page 7-23
lists IP fragment reassembly signatures with the parameters that you can configure for IP
IP Fragment Reassembly Signatures
Chapter 7
Parameter With Default Value
Specify Max Fragments 10000
None
Specify Max Datagram Size 65536
None
None
Specify Max Partial Datagrams 1000
Specify Max Small Frags 2
Specify Min Fragment Size 400
Specify Max Fragments per Datagram 170
Specify Fragment Reassembly Timeout 60
Specify Max Last Fragments 4
None
Defining Signatures
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents