Enabling Defense Against Malformed Packet Attacks

With defense against malformed packet attacks, the router checks the validity of received packets and filters out illegal packets, thus defending the CPU against attacks of IP packets with null load, null IGMP packets, LAND attack packets, Smurf attack packets, and packets with invalid TCP flag bits.

Procedure

  1. Run system-view

    The system view is displayed.

  2. Run cpu-defend policy policy-number

    The attack defense policy view is displayed.

  3. Perform either of the following operations as required:

    Defense against IPv4 malformed packet attacks can defend against attacks of various malformed packets, including IP packets with null load, null IGMP packets, LAND attack packets, Smurf attack packets, and packets with invalid TCP flag bits.

    Defense against IPv6 malformed packet attacks can defend against attacks of various malformed packets, including LAND attack packets, and packets with invalid TCP flag bits.

  4. Run commit

    The configuration is committed.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >