D-Link DGS-1210-28XS/ME [75/519] Command parameter

D-Link DGS-1210-52/ME rev.B [75/519] Command parameter
DGS-1210/ME Metro Ethernet Switch CLI Reference Guide
57
11
DOS PREVENTION COMMANDS
The DoS Prevention commands in the Command Line Interface (CLI) are listed (along with the appropriate
parameters) in the following table.
Command
Parameter
config dos_prevention
dos_type
[ {land_attack | blat_attack | smurf_attack | tcp_null_scan | tcp_xmascan |
tcp_synfin | tcp_syn_srcport_less_1024} | all] {action drop} | state [enable |
disable] ] }
show dos_prevention
{ land_attack | blat_attack | smurf_attack | tcp_null_scan | tcp_xmascan |
tcp_synfin | tcp_syn_srcport_less_1024 }
enable dos_prevention
trap_log
disable dos_prevention
trap_log
Each command is listed in detail, as follows:
config dos_prevention dos_type
Purpose U
sed to discard the L3 control packets sent to CPU from specific
ports.
Syntax
config dos_prevention dos_type [ {land_attack | blat_attack |
smurf_attack | tcp_null_scan | tcp_xmascan | tcp_synfin |
tcp_syn_srcport_less_1024} | all] {action drop} | state [enable |
disable] ] }
Description
The config dos_prevention dos_type
command is used to
configure the prevention of DoS attacks, and incluDGS
state and
action. The packets matching will be used by the hardware. For a
specific type of attack, the content of the packet, regardless of the
receipt port or destination port, will be matc
hed against a specific
pattern.
Parameters The type of DoS attack. Possible values are as follows:
land_attack, blat_attack, smurf_attack, tcp_null_scan, tcp_xmascan
tcp_synfin and tcp_syn_srcport_less_1024.
By default, prevention for all types of DoS are enabled except for
tcp_syn_srcport_less_1024.
action [drop | mirror] - When enabling DoS prevention, the following
actions can be taken.
drop Drop the attack packets.
mirror Mirror the packet to other port for further process.
priority <value (0-7)> Change packet priority by the Switch from 0
to 7.
If the priority is not specified, the original priority will be used.
rx_rate [no_limit | <value (64-1024000)>] controls the rate of the
received DoS attack packets. If not specified, the default action is

Содержание

Похожие устройства

Скачать