Dos-control tcpfrag – Dell PowerEdge M805 User Manual

Page 174

Advertising
background image

142

Denial of Service Commands

www

.dell.com | support.dell.com

Control Flags set to 0 and TCP Sequence Number set to 0, having TCP Flags FIN, URG, and PSH
set and TCP Sequence Number set to 0, or having TCP Flags SYN and FIN both set, the packets
are dropped.

Syntax

dos-control tcpflag

no dos-control tcpflag

Default Configuration

Denial of Service is disabled.

Command Mode

Global Configuration mode.

User Guidelines

This command has no user guidelines.

Example

The following example activates TCP Flag Denial of Service protections.

console(config)#dos-control tcpflag

dos-control tcpfrag

Use the dos-control tcpfrag command in Global Configuration mode to enable TCP Fragment
Denial of Service protection. If the mode is enabled, Denial of Service prevention is active for this
type of attack. If packets ingress having IP Fragment Offset equal to one (1), the packets are
dropped.

Syntax

dos-control tcpfrag

no dos-control tcpfrag

Default Configuration

Denial of Service is disabled.

Command Mode

Global Configuration mode

User Guidelines

This command has no user guidelines.

Advertising