10-Security Configuration Guide

HomeSupportSwitchesH3C S12500 Switch SeriesConfigure & DeployConfiguration GuidesH3C S12500 Configuration Guides-Release7374-6W73110-Security Configuration Guide
15-Attack detection and prevention configuration

Overview

Attack detection and prevention enables a device to detect attacks by inspecting arriving packets, and to take prevention actions to protect a private network. Prevention actions include logging, packet dropping, blacklisting, and client verification.

The device supports only TCP fragment attack prevention.

Configuring TCP fragment attack prevention

IMPORTANT

IMPORTANT:

·     This feature is supported only on EC1, EF and FG cards. EC1 cards refer to cards suffixed with EC1, EF cards refer to cards suffixed with EF, and FG cards refer to cards suffixed with FG.

·     The device does not support filtering first fragments in which the TCP header is smaller than 20 bytes.

 

The TCP fragment attack prevention feature enables the device to drop attack TCP fragments to prevent TCP fragment attacks that traditional packet filter cannot detect. As defined in RFC 1858, attack TCP fragments refer to the following TCP fragments:

·     First fragments in which the TCP header is smaller than 20 bytes.

·     Non-first fragments with a fragment offset of 8 bytes (FO=1).

Configuration restrictions and guidelines

When you configure TCP fragment attack prevention, follow these restrictions and guidelines:

·     For this feature to take effect, you must execute the acl hardware-mode ipv6 enable command first.

Configuration procedure

To configure TCP fragment attack prevention:

 

Step

Command

Remarks

1.     Enter system view.

system-view

N/A

2.     Enable TCP fragment attack prevention.

attack-defense tcp fragment enable

By default, TCP fragment attack prevention is enabled.

 

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Intelligent Storage
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
  • Technical Blogs
All Support
  • Become A Partner
  • Partner Policy & Program
  • Global Learning
  • Partner Sales Resources
  • Partner Business Management
  • Service Business
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网