07-Security Configuration Guide

HomeSupportConfigure & DeployConfiguration GuidesH3C Access Controllers Configuration Guides(E3703P61 R2509P61 R3709P61 R2609P61 R3509P61)-6W10207-Security Configuration Guide
25-Attack detection and protection configuration

Configuring attack detection and protection

Overview

Attack detection and protection enables a device to detect attacks by inspecting arriving packets and to take protection actions, such as packet dropping, to protect a private network.

The device supports only TCP fragment attack protection.

Configuring TCP fragment attack protection

The TCP fragment attack protection feature enables the device to drop attack TCP fragments to prevent TCP fragment attacks that packet filter cannot detect. As defined in RFC 1858, attack TCP fragments refer to the following TCP fragments:

·     First fragments in which the TCP header is smaller than 20 bytes.

·     Non-first fragments with a fragment offset of 8 bytes (FO=1).

To configure TCP fragment attack protection:

 

Step

Command

Remarks

1.     Enter system view.

system-view

N/A

2.     Enable TCP fragment attack protection.

attack-defense tcp fragment enable

By default, TCP fragment attack protection is enabled.

 

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
All Support
  • Become a Partner
  • Partner Resources
  • Partner Business Management
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网