Configuring Dos Information - Dell PowerEdge M420 Configuration Manual

Dell powerconnect m8024-k user's configuration guide
Hide thumbs Also See for PowerEdge M420:
Table of Contents

Advertisement

Command
show crypto certificate
mycertificate
show ip http server
secure status
show ip http server
status

Configuring DoS Information

Beginning in Privileged EXEC mode, use the following commands to specify
settings to help prevent DoS attacks on the switch.
Command
configure
dos-control sipdip
dos-control firstfrag
size
[
]
dos-control tcpfrag
dos-control tcpflag
dos-control l4port
228
Controlling Management Access
Purpose
View the SSL certificates of your switch.
Display the HTTPS server configuration.
Display the HTTP server configuration.
Purpose
Enter Global Configuration mode.
Enable Source IP Address = Destination IP Address
(SIP=DIP) Denial of Service protection.
If packets ingress with SIP=DIP , the packets is dropped if
the mode is enabled.
Enable Minimum TCP Header Size Denial of Service
size
protection, where
255).
Enable TCP Fragment Denial of Service protection.
If packets ingress having IP Fragment Offset equal to one
(1), the packets are dropped.
Enable TCP Flag Denial of Service protections.
If packets ingress having TCP Flag SYN set and a source
port less than 1024, having TCP Control Flags set to 0 and
TCP Sequence Number set to 0, having TCP Flags FIN,
URG, and PSH set and TCP Sequence Number set to 0, or
having TCP Flags SYN and FIN both set, the packets are
dropped.
Enable L4 Port Denial of Service protection.
If packets ingress having Source TCP/UDP Port Number
equal to Destination TCP/UDP Port Number, the packets
are dropped.
is the TCP header size. (Range: 0-

Advertisement

Table of Contents
loading

Table of Contents