Reference Guide

Table Of Contents
dos-control icmpfrag
Note
This command is only supported on the BCM56224, BCM56514, BCM56624, BCM56634,
BCM56636 and BCM56820 and BCM5621x platforms.
This command enables ICMP Fragment Denial of Service protection. If the mode is enabled, Denial of
Service prevention is active for this type of attack. If packets ingress having fragmented ICMP packets,
the packets will be dropped if the mode is enabled.
Default Disabled
Format dos-control icmpfrag
Mode Global Config
no dos-control icmpfrag
This command disabled ICMP Fragment Denial of Service protection.
Format no dos-control icmpfrag
Mode Global Config
show dos-control
This command displays Denial of Service configuration information.
Format
show dos-control
Mode Privileged EXEC
Note
Some of the following information displays only if you are using the BCM56224, BCM56514,
BCM56624, BCM56634, BCM56636 and BCM56820 and BCM5621x platforms.
Column Meaning
First Fragment Mode The administrative mode of First Fragment DoS prevention. When enabled, this causes
the switch to drop packets that have a TCP header smaller then the configured Min TCP
Hdr Size.
Min TCP Hdr Size The minimum TCP header size the switch will accept if First Fragment DoS prevention is
enabled.
ICMPv4 Mode The administrative mode of ICMPv4 DoS prevention. When enabled, this causes the
switch to drop ICMP packets that have a type set to ECHO_REQ (ping) and a size greater
than the configured ICMPv4 Payload Size.
Max ICMPv4 Payload
Size
The maximum ICMPv4 payload size to accept when ICMPv4 DoS protection is enabled.
ICMPv6 Mode The administrative mode of ICMPv6 DoS prevention. When enabled, this causes the
switch to drop ICMP packets that have a type set to ECHO_REQ (ping) and a size greater
than the configured ICMPv6 Payload Size.
Switching Commands
ExtremeSwitching 200 Series: Command Reference Guide for version 01 .02.04.0007 482