Dos-Control Firstfrag; Dos-Control Tcpfrag; Dos-Control Tcpflag - Ubiquiti EDGESWITCH ES-24-250W Command Reference Manual

Hide thumbs Also See for EDGESWITCH ES-24-250W:
Table of Contents

Advertisement

EdgeSwitch CLI Command Reference
no dos-control sipdip
This command disables Source IP address = Destination IP address (SIP = DIP) Denial of Service prevention .
no dos-control sipdip
Format
Mode
Global Config

dos-control firstfrag

This command enables Minimum TCP Header Size Denial of Service protection . If the mode is enabled, Denial
of Service prevention is active for this type of attack . If packets ingress having a TCP Header Size smaller then
the configured value, the packets will be dropped if the mode is enabled . The default is disabled . If you enable
dos-control
firstfrag, but do not provide a Minimum TCP Header Size, the system sets that value to 20 .
Default
disabled (20)
dos-control firstfrag [0-255]
Format
Mode
Global Config
no dos-control firstfrag
This command sets Minimum TCP Header Size Denial of Service protection to the default value of disabled .
no dos-control firstfrag
Format
Mode
Global Config

dos-control tcpfrag

This command enables TCP Fragment Denial of Service protection . If the mode is enabled, Denial of Service
prevention is active for this type of attack . If packets ingress having IP Fragment Offset equal to one (1), the
packets will be dropped if the mode is enabled .
Default
disabled
dos-control tcpfrag
Format
Mode
Global Config
no dos-control tcpfrag
This command disabled TCP Fragment Denial of Service protection .
no dos-control tcpfrag
Format
Mode
Global Config

dos-control tcpflag

This command enables TCP Flag Denial of Service protections . If the mode is enabled, Denial of Service
prevention is active for this type of attacks . If packets ingress having TCP Flag SYN set and a source port less
than 1024 or having TCP Control Flags set to 0 and TCP Sequence Number set to 0 or having TCP Flags FIN, URG,
and PSH set and TCP Sequence Number set to 0 or having TCP Flags SYN and FIN both set, the packets will be
dropped if the mode is enabled .
Default
disabled
dos-control tcpflag
Format
Mode
Global Config
no dos-control tcpflag
This command sets disables TCP Flag Denial of Service protections .
no dos-control tcpflag
Format
Mode
Global Config
Ubiquiti Networks, Inc.
Switching Commands
307

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Edgeswitch es-24-500wEdgeswitch es-48-750wEdgeswitch es-48-500wEdgeswitch es-24-250w

Table of Contents