09-Security Command Reference

HomeSupportSwitchesS5136 SeriesS5136S-EI SeriesTechnical DocumentsReference GuidesCommand ReferencesH3C S5136S-EI Switch Series Command References-6W10009-Security Command Reference
23-Attack detection and prevention commands
Title Size Download
23-Attack detection and prevention commands 40.05 KB

Attack detection and prevention commands

attack-defense tcp fragment enable

Use attack-defense tcp fragment enable to enable TCP fragment attack prevention.

Use undo attack-defense tcp fragment enable to disable TCP fragment attack prevention.

Syntax

attack-defense tcp fragment enable

undo attack-defense tcp fragment enable

Default

TCP fragment attack prevention is enabled.

Views

System view

Predefined user roles

network-admin

Usage guidelines

This command enables the device to drop attack TCP fragments to prevent TCP fragment attacks that the packet filter cannot detect. As defined in RFC 1858, attack TCP fragments refer to the following TCP fragments:

·     First fragments in which the TCP header is smaller than 20 bytes.

·     Non-first fragments with a fragment offset of 8 bytes (FO=1).

TCP fragment attack prevention takes precedence over single-packet attack prevention. When both are used, incoming TCP packets are processed first by TCP fragment attack prevention and then by the single-packet attack defense policy.

Examples

# Enable TCP fragment attack prevention.

<Sysname> System-view

[Sysname] attack-defense tcp fragment enable

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Intelligent Storage
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
  • Technical Blogs
All Support
  • Become A Partner
  • Partner Policy & Program
  • Global Learning
  • Partner Sales Resources
  • Partner Business Management
  • Service Business
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网