Reference Guide

Table Of Contents
no dos-control sipdip
This command disables Source IP address = Destination IP address (SIP = DIP) Denial of Service
prevention.
Format no dos-control sipdip
Mode Global Config
dos-control firstfrag
This command enables Minimum TCP Header Size Denial of Service protection. If the mode is enabled,
Denial of Service prevention is active for this type of attack. If packets ingress having a TCP Header Size
smaller then the configured value, the packets will be dropped if the mode is enabled. The default is
disabled. If you enable dos-control firstfrag, but do not provide a Minimum TCP Header Size, the system
sets that value to 20.
Default Disabled (20)
Format dos-control firstfrag [0-255]
Mode Global Config
no dos-control firstfrag
This command sets Minimum TCP Header Size Denial of Service protection to the default value of
disabled.
Format
no dos-control firstfrag
Mode Global Config
dos-control tcpfrag
This command enables TCP Fragment Denial of Service protection. If the mode is enabled, Denial of
Service prevention is active for this type of attack and packets that have a TCP payload in which the IP
payload length minus the IP header size is less than the minimum allowed TCP header size are dropped.
Default
Disabled
Format dos-control tcpfrag
Mode Global Config
no dos-control tcpfrag
This command disables TCP Fragment Denial of Service protection.
Format
no dos-control tcpfrag
Mode Global Config
Switching Commands
ExtremeSwitching 200 Series: Command Reference Guide for version 01 .02.04.0007 475