Filter and Firewall
Left running head:
Chapter name (automatic)
508
Beta
Beta
OmniAccess 5510 Unified Services Gateway CLI Command Reference Guide
Alcatel-Lucent
ICMP
-
PING
-
OF
-
DEATH
icmp-ping-of-death
[{
max-frag-num
|
max-total-length
} <
1-
4294967295
>]
D
ESCRIPTION
This command is entered in the Firewall-Attack Sub Configuration Mode. The
TCP/IP specification requires a specific packet size for datagram transmission.
Many ping implementations allow you to specify a larger packet size if desired. A
grossly oversized ICMP packet can trigger a range of adverse system reactions
such as denial of service (DoS), crashing, freezing, and rebooting. This command
is also placed in the DoS attack prevention list to secure the system from this
attack.
P
ARAMETERS
D
EFAULT
V
ALUE
•
Number of the maximum fragments allowed in one ping packet, default value is 50
•
Number of maximum length of the whole ping packet total, default value is 65507
E
XAMPLE
ALU(config-firewall-attack-A1)# icmp-ping-of-death max-frag-num
100
ICMP
-
REDIRECT
icmp-redirect
D
ESCRIPTION
This command is entered in the Firewall-Attack Sub Configuration Mode. This
command is not a default DoS setting. The above command can be included in
the DoS prevention list to avoid this kind of attacks.
P
ARAMETERS
None.
E
XAMPLE
ALU(config-firewall-attack-A1)# icmp-redirect
Parameter
Description
max-frag-num <1-4294967295>
Number of the maximum fragments
allowed in one ping packet.
max-total-length <1-
4294967295>
Number of maximum length of the whole
ping packet total.