Table 57: Dos Protection Commands; Denial Of Service Protection - Edge-Core ECS4210-12P Reference Manual

12/28-port gigabit ethernet layer 2 switch
Hide thumbs Also See for ECS4210-12P:
Table of Contents

Advertisement

Chapter 8
| General Security Measures

Denial of Service Protection

Denial of Service Protection
Example
Console#show ip arp inspection vlan 1
VLAN ID
DAI Status
--------
---------------
1
disabled
Console#
A denial-of-service attack (DoS attack) is an attempt to block the services provided
by a computer or network resource. This kind of attack tries to prevent an Internet
site or service from functioning efficiently or at all. In general, DoS attacks are
implemented by either forcing the target to reset, to consume most of its resources
so that it can no longer provide its intended service, or to obstruct the
communication media between the intended users and the target so that they can
no longer communicate adequately.
This section describes commands used to protect against DoS attacks.

Table 57: DoS Protection Commands

Command
Global Protection
dos-protection
Protection for ICMP
dos-protection icmp flood
dos-protection icmp nuke
dos-protection icmp ping-of-
death
dos-protection icmp smurf
Protection for IPv4
dos-protection ip invalid-
destination-ip-address
dos-protection ip invalid-header-
length
dos-protection ip invalid-ip-
address
dos-protection ip invalid-source-
ip-address
Protection for IPv6
dos-protection ipv6 invalid-
destination-ip-address
dos-protection ipv6 invalid-
header-length
ACL Name
--------------------
sales
Function
Enables or disables DoS protection globally
Protects against ICMP flooding attacks
Protects against ICMP nuke attacks
Protects against ICMP ping-of-death attacks
Protects against smurf attacks
Protects against invalid IP destination address
attacks
Protects against invalid IP header-length attacks
Protects against attacks in which hackers replace
the source or destination IP address
Protects against spoofing with an invalid IP address GC
Protects against invalid IPv6 destination address
attacks
Protects against invalid IPv6 header-length attacks
– 294 –
ACL Status
--------------------
static
Mode
GC
GC
GC
GC
GC
GC
GC
GC
GC
GC
GC
GC
GC

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ecs4210-12tEcs4210-28pEcs4210-28t

Table of Contents