Netgear GS110TP GS108Tv2/GS110TP Software Reference Manual - Page 50

Denial of Service Min TCP Hdr Size

Page 50 highlights

GS108T and GS110TP Smart Switch Software Administration Manual To configure individual DoS settings: 1. Select the types of DoS attacks for the switch to monitor and block and configure any associated values, as the following list describes. • Denial of Service SIP=DIP. Enable or disable this option by selecting the appropriate radio button. Enabling SIP=DIP DoS prevention causes the switch to drop packets that have a source IP address equal to the destination IP address. The factory default is Disable. • Denial of Service First Fragment. Enable or disable this option by selecting the appropriate radio button. Enabling First Fragment DoS prevention causes the switch to drop packets that have a TCP header smaller than the configured Min TCP Hdr Size. The factory default is Disable. • Denial of Service Min TCP Hdr Size. Specify the Min TCP Hdr Size allowed. If First Fragment DoS prevention is enabled, the switch will drop packets that have a TCP header smaller than this configured Min TCP Hdr Size. The factory default is 20 bytes. • Denial of Service TCP Fragment. Enable or disable this option by selecting the appropriate radio button. Enabling TCP Fragment DoS prevention causes the switch to drop packets that have an IP fragment offset equal to 1. The factory default is Disable. • Denial of Service TCP Flag. Enable or disable this option by selecting the appropriate radio button. Enabling TCP Flag DoS prevention causes the switch to drop packets that have TCP flag SYN set and TCP source port less than 1024 or TCP control flags set to 0 and TCP sequence number set to 0 or TCP flags FIN, URG, and PSH set and TCP sequence number set to 0 or both TCP flags SYN and FIN set. The factory default is Disable. • Denial of Service L4 Port. Enable or disable this option by selecting the appropriate radio button. Enabling L4 Port DoS prevention causes the switch to drop packets that have TCP/ UDP source port equal to TCP/UDP destination port. The factory default is Disable. • Denial of Service ICMP. Enable or disable this option by selecting the appropriate radio button. Enabling ICMP DoS prevention causes the switch to drop ICMP packets that have a type set to ECHO_REQ (ping) and a size greater than the configured ICMP packet size. The factory default is Disable. • Denial of Service Max ICMP Size. Specify the Max ICMP packet size allowed. If ICMP DoS prevention is enabled, the switch will drop ICMP ping packets that have a size greater then this configured Max ICMP packet size. The factory default is Disable. 2. If you change any of the DoS settings, click Apply to apply the changes to the switch. 3. Click Cancel to cancel the configuration on the screen and reset the data on the screen to the latest value of the switch. 2-14 v1.0, April 2010 Configuring System Information

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302

GS108T and GS110TP Smart Switch Software Administration Manual
2-14
Configuring System Information
v1.0, April 2010
To configure individual DoS settings:
1.
Select the types of DoS attacks for the switch to monitor and block and configure any
associated values, as the following list describes.
Denial of Service SIP=DIP
. Enable or disable this option by selecting the appropriate
radio button. Enabling SIP=DIP DoS prevention causes the switch to drop packets that
have a source IP address equal to the destination IP address. The factory default is Disable.
Denial of Service First Fragment
. Enable or disable this option by selecting the
appropriate radio button. Enabling First Fragment DoS prevention causes the switch to
drop packets that have a TCP header smaller than the configured Min TCP Hdr Size. The
factory default is Disable.
Denial of Service Min TCP Hdr Size
. Specify the Min TCP Hdr Size allowed. If First
Fragment DoS prevention is enabled, the switch will drop packets that have a TCP header
smaller than this configured Min TCP Hdr Size. The factory default is 20 bytes.
Denial of Service TCP Fragment
. Enable or disable this option by selecting the
appropriate radio button. Enabling TCP Fragment DoS prevention causes the switch to
drop packets that have an IP fragment offset equal to 1. The factory default is Disable.
Denial of Service TCP Flag
. Enable or disable this option by selecting the appropriate
radio button. Enabling TCP Flag DoS prevention causes the switch to drop packets that
have TCP flag SYN set and TCP source port less than 1024 or TCP control flags set to 0
and TCP sequence number set to 0 or TCP flags FIN, URG, and PSH set and TCP
sequence number set to 0 or both TCP flags SYN and FIN set. The factory default is
Disable.
Denial of Service L4 Port
. Enable or disable this option by selecting the appropriate radio
button. Enabling L4 Port DoS prevention causes the switch to drop packets that have TCP/
UDP source port equal to TCP/UDP destination port. The factory default is Disable.
Denial of Service ICMP
. Enable or disable this option by selecting the appropriate radio
button. Enabling ICMP DoS prevention causes the switch to drop ICMP packets that have
a type set to ECHO_REQ (ping) and a size greater than the configured ICMP packet size.
The factory default is Disable.
Denial of Service Max ICMP Size
. Specify the Max ICMP packet size allowed. If ICMP
DoS prevention is enabled, the switch will drop ICMP ping packets that have a size
greater then this configured Max ICMP packet size. The factory default is Disable.
2.
If you change any of the DoS settings, click
Apply
to apply the changes to the switch.
3.
Click
Cancel
to cancel the configuration on the screen and reset the data on the screen to the
latest value of the switch.