User Manual

Table Of Contents
Manage Device Security
522
M4200 and M4300 Series ProSAFE Managed Switches Web Management User Manual
If ICMPv6 DoS prevention is enabled, the switch drops IPv6 ICMP ping packets with a
size greater than the configured maximum ICMPv6 packet size. Its range is 0 to 16376.
The default value is 512.
11. Select the Denial of Service First Fragment Disable or Enable radio button.
This enables First Fragment DoS prevention, which causes the switch to check DoS
options on first fragment IP packets when switch are receiving fragmented IP packets.
Otherwise, switch ignores the first fragment IP packages.The factory default is Disable.
12. Select the Denial of Service ICMP Fragment Disable or Enable radio button.
Enabling ICMP Fragment DoS prevention causes the switch to drop ICMP Fragmented
packets. The factory default is Disable.
13. Select the Denial of Service SIP=DIP Disable or Enable radio button.
Enable SIP=DIP DoS prevention causes the switch to drop packets with a source IP
address equal to the destination IP address. The factory default is Disable.
14. Select the Denial of Service SMAC=DMAC Disable or Enable radio button.
Enabling SMAC=DMAC DoS prevention causes the switch to drop packets with a source
MAC address equal to the destination MAC address. The factory default is Disable.
15. Select the Denial of Service TCP FIN&URG&PSH Disable or Enable radio button.
Enabling TCP FIN & URG & PSH DoS prevention causes the switch to drop packets with
TCP Flags FIN, URG, and PSH set and TCP Sequence Number=0. The factory default is
Disable.
16. Select the Denial of Service TCP Flag&Sequence Disable or Enable radio button.
Enabling TCP Flag DoS prevention causes the switch to drop packets with TCP control
flags set to 0 and TCP sequence number set to 0. The factory default is Disable.
17. Select the Denial of Service TCP Fragment Disable or Enable radio button.
Enabling TCP Fragment DoS prevention causes the switch to drop packets as follows:
First TCP fragments with a TCP payload: IP_Payload_Length - IP_Header_Size <
Min_TCP_Header_Size.
The factory default is Disable.
18. Select the Denial of Service TCP Offset Disable or Enable radio button.
Enabling TCP Offset DoS prevention causes the switch to drop packets with a TCP
header Offset=1. The factory default is Disable.
19. Select the Denial of Service TCP Port Disable or Enable radio button.
Enabling TCP Port DoS prevention causes the switch to drop packets with TCP source
port equal to TCP destination port. The factory default is Disable.
20. Select the Denial of Service TCP SYN Disable or Enable radio button.
Enabling
TCP SYN DoS prevention causes the switch to drop packets with
TCP flags
SYN set. The factory default is Disable.