
14 - 12 WiNG CLI Reference Guide
Example
rfs7000-37FABE(config-fw-policy-default)#ip dos tcp-max-incomplete high 8
rfs7000-37FABE(config-fw-policy-default)#
rfs7000-37FABE(config-fw-policy-default)# ip dos land log-only log-level warnings
rfs7000-37FABE(config-fw-policy-default)#
rfs7000-37FABE(config-fw-policy-test)#ip tcp adjust-mss 475
rfs7000-37FABE(config-fw-policy-test)#
For all the above DoS attacks, the following log-levels can be set
• alerts – Immediate action needed (level 1)
• critical – Critical conditions (level 2)
• <0-8> – Select one numerical log level. All messages with
and below this severity are logged
• emergencies – System is unusable (level 0)
• errors – Error conditions (level 3)
• warnings – Warning conditions (level 4
• notifications – Normal but significant conditions
(level 5)
• informational – Informational messages (level 6)
• debugging – Debugging messages (level 7)
• none –Disable logging (level 8)
• tcp -max-incomplete – Configures the maximum half-open TCP
connections in the system
• high <1-1000> – Sets the upper threshold value
between 1 and 1000
• low <1-1000> – Sets the lower threshold value
between 1 and1000
tcp [adjust-mss <472-1460> |
optimize-unnecessary-resends
|recreate-flow-on-out-of-state-
syn|
validate-icmp-unreachable |
validate-rst-ack-number |
validate-rst-seq-number]
Configures TCP protocol settings
• adjust-mss <472-1460> – Sets TCP MSS adjustment value
• <472-1460> – Sets the maximum value of TCP MSS option
<472-1460>
• optimize-unnecessary-resends – Enables checking of unnecessary
resend of TCP packets
• recreate-flow-on-out-of-state-syn – Allows a SYN packet to delete
a n ol d fl o w i n T C P _F I N_ F IN _ ST AT E an d T C P _ C LO S E D _ S T AT E
states and create a new flow
• validate-icmp-unreachable – Enables checking of sequence number
in ICMP unreachable error packets which aborts an established TCP
flow
• validate-rst-ack-number – Enables checking of acknowledgement
number in RST packets which aborts a TCP flow in SYN (sent) state
• validate-rst-seq-number – Enables checking of sequence number in
RST packets which aborts an established TCP flow
Kommentare zu diesen Handbüchern