
FIREWALL-POLICY 14 - 11
Parameters
dos {ascend|
bcast-mcast-icmp
|chargen|fraggle|
ftp-bounce|invalid-protocol|
ip-ttl-zero|ipspoof|land|
option-route|
router-solicit|router-advt|
smurf|snork|tcp-bad-
sequence|tcp-fin-scan|
tcp-intercept|tcp-max-
incomplete| tcp-null-scan|
tcp-post-syn|
tcp-xmas-scan |tcphdrfrag
|twinge|udp-short-hdr}
[drop-only|log-and-drop|
log-only]log-level [<0-8>|
alerts|critical|debugging|
|emergencies|
errors|informational|none|notif
ications|
warnings]
Configures the Denial of Service (DOS) attack parameter
• ascend – Enables ascend DoS checks
• bcast-mcast-icmp – Detects broadcast/multicast ICMP traffic as an
attack
• chargen – Enables chargen DoS checks
• fraggle – Enables fraggle DoS checks
• ftp-bounce – Enables FTP bounce logs and sets the logging levels
• invalid-protocol – Enables an invalid protocol DoS attack check and
sets the logging levels for this attack
• ip-ttl-zero – Enables a TCP IP TTL ZERO DoS attack check
• ipspoof – Enables an IPSPOOF DoS attack check
• land – Enables a LAND DoS attack check
• option-route – Enables IP option route check
• router-advt – Enables an ICMP router advertisement check
• router-solicit – Enables an ICMP router solicit check
• smurf log – Enables a smurf attack check
• snork – Enables a packet check
• tcp-intercept – Enables a TCP intercept
• tcp-bad-sequence – Enables a TCP BAD SEQUENCE DoS attack check
• tcp-fin-scan – Enables a TCP FIN SCAN DoS attack check
• tcp-null-scan – Enables a TCP NULL SCAN DoS attack check
• tcp-post-syn – Enables a TCP Post Syn DoS attack check
• tcp-xmas-scan – Enables a TCP XMAS SCAN DoS attack check
• tcphdrfrag – Enables a TCP Header Fragmentation attach check
• twinge – Enables a twinge check
• udp-short-hdr – Enables a UDP short header DoS attack check
• winnuke – Enables WINNUKE DoS attack
For all the above, the following parameters are common:
• drop-only – Drops the packet only
• log-and-drop log-level – Logs the details and drops the packet
• log-only log-level – Logs the details only
• log-level [<0-8>|alerts|critical|debugging| |emergencies|errors|
informational|none|notifications|warnings] – Configures the log
level for a DoS check
Kommentare zu diesen Handbüchern