Configuring Attack Checking; Enabling The Secure Router Os Firewall - HP ProCurve Secure Router 7203 dl Advanced Management And Configuration Manual

Secure router
Hide thumbs Also See for ProCurve Secure Router 7203 dl:
Table of Contents

Advertisement

ProCurve Secure Router OS Firewall—Protecting the Internal, Trusted Network

Configuring Attack Checking

4-14
Configuring Attack Checking
To configure the Secure Router OS firewall to block attacks, you only have to:
enable the firewall
You can also:
enable and disable optional checks
check reflexive traffic
enable stealth mode

Enabling the Secure Router OS Firewall

To enable the firewall, enter the following command from the global configu-
ration mode context:
ProCurve(config)# ip firewall
When the Secure Router OS firewall is enabled, it automatically blocks the
attacks and types of packets shown in Table 4-2.
Table 4-2.
Packets Automatically Dropped by the Secure Router OS Firewall
Packet
larger than the IP max (65,535 bytes)
fragmented packets with errors when
reconstructed
ping response that is not part of an active
session
source address does not match any of the routes
for interface on which the packet arrived
Associated Attack
Ping of death
• Syndrop
• Targa
• Nestea
• Newtear
• TearDrop
• Opentear
• Bonk
• Boink
Smurf attack
IP spoofing

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve secure router 7102 dl

Table of Contents