To do…

 

Use the command…

 

Remarks

 

Enter system view

 

system-view

 

 

 

 

 

 

 

Configure TCP synwait

 

tcp timer syn-timeout

 

Optional

 

 

 

By default, the timeout value is 75

 

timer’s timeout value

 

time-value

 

 

 

 

seconds.

 

 

 

 

 

 

 

 

 

 

 

 

Configure TCP finwait timer’s

 

tcp timer fin-timeout

 

Optional

 

 

 

By default, the timeout value is

 

timeout value

 

time-value

 

 

 

 

675 seconds.

 

 

 

 

 

 

 

 

 

 

 

Configure the size of TCP

 

 

Optional

 

 

tcp window window-size

By default, the buffer is 8

 

receive/send buffer

 

 

 

 

kilobytes.

 

 

 

 

 

 

 

 

 

 

Disabling Sending of ICMP Error Packets

Sending error packets is a major function of ICMP protocol. In case of network abnormalities, ICMP packets are usually sent by the network or transport layer protocols to notify corresponding devices so as to facilitate control and management.

By default, the device supports sending ICMP redirect and destination unreachable packets.

Although sending ICMP error packets facilitate control and management, it still has the following disadvantages:

z z

z

z

Sending a lot of ICMP packets will increase network traffic.

If receiving a lot of malicious packets that cause it to send ICMP error packets, the device’s performance will be reduced.

As the ICMP redirection function increases the routing table size of a host, the host’s performance will be reduced if its routing table becomes very large.

If a host sends malicious ICMP destination unreachable packets, end users may be affected.

To prevent the above mentioned problems, you can disable the device from sending such ICMP error packets.

Follow these steps to disable sending of ICMP error packets:

To do…

Use the command…

Remarks

Enter system view

system-view

 

 

 

Disable sending of ICMP

undo icmp redirect send

Required

redirects

Enabled by default

 

 

 

 

Disable sending of ICMP

 

Required

destination unreachable

undo icmp unreach send

Enabled by default

packets

 

 

 

 

 

 

2-2

Page 310
Image 310
3Com WX3000 operation manual Disabling Sending of Icmp Error Packets