Dos-control tcpfrag – Dell POWEREDGE M905 User Manual
Page 174
142
Denial of Service Commands
www
.dell.com | support.dell.com
Control Flags set to 0 and TCP Sequence Number set to 0, having TCP Flags FIN, URG, and PSH
set and TCP Sequence Number set to 0, or having TCP Flags SYN and FIN both set, the packets
are dropped.
Syntax
dos-control tcpflag
no dos-control tcpflag
Default Configuration
Denial of Service is disabled.
Command Mode
Global Configuration mode.
User Guidelines
This command has no user guidelines.
Example
The following example activates TCP Flag Denial of Service protections.
console(config)#dos-control tcpflag
dos-control tcpfrag
Use the dos-control tcpfrag command in Global Configuration mode to enable TCP Fragment
Denial of Service protection. If the mode is enabled, Denial of Service prevention is active for this
type of attack. If packets ingress having IP Fragment Offset equal to one (1), the packets are
dropped.
Syntax
dos-control tcpfrag
no dos-control tcpfrag
Default Configuration
Denial of Service is disabled.
Command Mode
Global Configuration mode
User Guidelines
This command has no user guidelines.