Security CLI Commands
584
2/1553-ZAT 759 94 Uen B – December 2005
19.39
security set IDS MaxPING
19.39.1 Syntax
security set IDS MaxPING <max>
19.39.2 Description
This command sets the maximum number of pings per second that are
allowed before an Echo Storm is detected. Echo Storm is a DOS (Denial of
Service) attack. An attacker sends oversized ICMP datagrams to the system
using the ‘ping’ command. This can cause the system to crash, freeze or
reboot, resulting in denial of service to legitimate users.
Once the maximum number of pings per second is reached, an attempted
DOS attack is detected.
Note:
This CLI command is
case-sensitive
. You must type the command
attributes exactly as they appear in the syntax section of this page. If
you do not use the same case-sensitive syntax, the command fails
and the CLI displays a syntax error message.
19.39.3 Options
The following table gives the range of values for each option which can be
specified with this command and a default value (if applicable).
Option Description
Default
value
max
The maximum number (per second) of
pings that are allowed before an Echo
Storm attempt is detected.
15
19.39.4 Example
-->
security set IDS MaxPING 25