Netgear GS752TS GS7xxTS-TPS Software Admin Manual - Page 48

Denial of Service TCP FIN&URG&PSH, Denial of Service TCP Flag &Sequence

Page 48 highlights

GS728TS, GS728TPS, GS752TS, and GS752TPS Gigabit Smart Switches • Denial of Service Max ICMPv6 Packet Size. Specify the maximum allowed IPv6 ICMP packet size. If ICMPv6 DoS prevention is enabled, the switch will drop IPv6 ICMP ping packets that have a size greater than this configured maximum ICMPv6 packet size. The range is 0 to 16376, and the default value (when enabled) is 512. • Denial of Service First Fragment. Enable or disable this option by selecting the appropriate radio button. Enabling First Fragment DoS prevention causes the switch to drop packets that have a TCP header smaller than the configured Min TCP Hdr Size. The factory default is Disable. • Denial of Service ICMP Fragment. Enable or disable this option by selecting the appropriate radio button. Enabling ICMP Fragment DoS prevention causes the switch to drop fragmented ICMP packets. The factory default is disabled. • Denial of Service SIP=DIP. Enable or disable this option by selecting the appropriate radio button. Enabling SIP=DIP DoS prevention causes the switch to drop packets that have a source IP address equal to the destination IP address. The factory default is Disable. • Denial of Service SMAC=DMAC. Enable or disable this option by selecting the appropriate radio button. Enabling SMAC=DMAC DoS prevention causes the switch to drop packets that have a source MAC address equal to the destination MAC address. The factory default is disabled. • Denial of Service TCP FIN&URG&PSH. Enable or disable this option by selecting the appropriate radio button. Enabling TCP FIN & URG & PSH DoS prevention causes the switch to drop packets that have TCP Flags FIN, URG, and PSH set and a TCP Sequence Number equal to 0. The factory default is disabled. • Denial of Service TCP Flag &Sequence. Enable or disable this option by selecting the appropriate radio button. Enabling TCP Flag DoS prevention causes the switch to drop packets that have TCP control flags set to 0 and TCP sequence number set to 0. The factory default is disabled. • Denial of Service TCP Fragment. Enable or disable this option by selecting the appropriate radio button. Enabling TCP Fragment DoS prevention causes the switch to drop packets that have a TCP payload where the IP payload length minus the IP header size is less than the minimum allowed TCP header size. The factory default is Disable. • Denial of Service TCP Offset. Enable or disable this option by selecting the appropriate radio button. Enabling TCP Offset DoS prevention causes the switch to drop packets that have a TCP header Offset=1. The factory default is disabled. • Denial of Service TCP Port. Enable or disable this option by selecting the appropriate radio button. Enabling TCP Port DoS prevention causes the switch to drop packets that have TCP source port equal to TCP destination port. The factory default is disabled. • Denial of Service TCP SYN. Enable or disable this option by selecting the appropriate radio button. Enabling TCP SYN DoS prevention causes the switch to drop packets that have TCP Flags SYN set and L4 source = 0-1023. The factory default is disabled. 48

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329

48
GS728TS, GS728TPS, GS752TS, and GS752TPS Gigabit Smart Switches
Denial of Service Max ICMPv6 Packet Size
. Specify the maximum allowed IPv6
ICMP packet size. If ICMPv6 DoS prevention is enabled, the switch will drop IPv6
ICMP ping packets that have a size greater than this configured maximum ICMPv6
packet size. The range is 0 to 16376, and the default value (when enabled) is 512.
Denial of Service First Fragment
. Enable or disable this option by selecting the
appropriate radio button. Enabling First Fragment DoS prevention causes the switch
to drop packets that have a TCP header smaller than the configured Min TCP Hdr
Size. The factory default is Disable.
Denial of Service ICMP Fragment
. Enable or disable this option by selecting the
appropriate radio button. Enabling ICMP Fragment DoS prevention causes the switch
to drop fragmented ICMP packets. The factory default is disabled.
Denial of Service SIP=DIP
. Enable or disable this option by selecting the appropriate
radio button. Enabling SIP=DIP DoS prevention causes the switch to drop packets
that have a source IP address equal to the destination IP address. The factory default
is Disable.
Denial of Service SMAC=DMAC
. Enable or disable this option by selecting the
appropriate radio button. Enabling SMAC=DMAC DoS prevention causes the switch
to drop packets that have a source MAC address equal to the destination MAC
address. The factory default is disabled.
Denial of Service TCP FIN&URG&PSH
. Enable or disable this option by selecting
the appropriate radio button. Enabling TCP FIN & URG & PSH DoS prevention
causes the switch to drop packets that have TCP Flags FIN, URG, and PSH set and a
TCP Sequence Number equal to 0. The factory default is disabled.
Denial of Service TCP Flag &Sequence
. Enable or disable this option by selecting
the appropriate radio button. Enabling TCP Flag DoS prevention causes the switch to
drop packets that have TCP control flags set to 0 and TCP sequence number set to 0.
The factory default is disabled.
Denial of Service TCP Fragment
. Enable or disable this option by selecting the
appropriate radio button. Enabling TCP Fragment DoS prevention causes the switch
to drop packets that have a TCP payload where the IP payload length minus the IP
header size is less than the minimum allowed TCP header size. The factory default is
Disable.
Denial of Service TCP Offset
. Enable or disable this option by selecting the
appropriate radio button. Enabling TCP Offset DoS prevention causes the switch to
drop packets that have a TCP header Offset=1. The factory default is disabled.
Denial of Service TCP Port
. Enable or disable this option by selecting the
appropriate radio button. Enabling TCP Port DoS prevention causes the switch to
drop packets that have TCP source port equal to TCP destination port. The factory
default is disabled.
Denial of Service TCP SYN
. Enable or disable this option by selecting the
appropriate radio button. Enabling TCP SYN DoS prevention causes the switch to
drop packets that have TCP Flags SYN set and L4 source = 0–1023. The factory
default is disabled.