ProCurve Secure Router OS Firewall—Protecting the Internal, Trusted Network
Configuring Attack Checking
4-14
Configuring Attack Checking
To configure the Secure Router OS firewall to block attacks, you only have to:
enable the firewall
You can also:
enable and disable optional checks
check reflexive traffic
enable stealth mode
Enabling the Secure Router OS Firewall
To enable the firewall, enter the following command from the global configu-
ration mode context:
ProCurve(config)# ip firewall
When the Secure Router OS firewall is enabled, it automatically blocks the
attacks and types of packets shown in Table 4-2.
Table 4-2.
Packets Automatically Dropped by the Secure Router OS Firewall
Packet
larger than the IP max (65,535 bytes)
fragmented packets with errors when
reconstructed
ping response that is not part of an active
session
source address does not match any of the routes
for interface on which the packet arrived
Associated Attack
Ping of death
• Syndrop
• Targa
• Nestea
• Newtear
• TearDrop
• Opentear
• Bonk
• Boink
Smurf attack
IP spoofing
Need help?
Do you have a question about the ProCurve Secure Router 7203 dl and is the answer not in the manual?
Questions and answers