AT-S62 Command Line User’s Guide

SET DOS TEARDROP

Syntax

set dos teardrop port=port state=enabledisable [mirrorport=autoport]

Parameters

 

 

port

Specifies the switch ports on which you want to

 

enable or disable this DoS defense. You can select

 

more than one port at a time.

state

Specifies the state of the DoS defense. The options

 

are:

 

 

enable

Activates the defense.

 

disable

Deactivates the defense. This is the default.

mirrorport

Specifies a port where invalid traffic is copied. You can

 

specify only one port.

Description

This command activates and deactivates the Teardrop DoS defense.

In this DoS attack, an attacker sends a packet in several fragments with a bogus offset value, used to reconstruct the packet, in one of the fragments to a victim. This results in the victim being unable to reassemble the packet, possibly causing it to freeze operations.

The defense mechanism for this type of attack has all ingress IP traffic received on a port sent to the switch’s CPU. The CPU samples related, consecutive fragments, checking for fragments with invalid offset values. If one is found, the following occurs:

The switch sends a trap to the management workstations.

The switch port discards the fragment with the invalid offset and, for a one minute period, discards all ingress IP fragments on the port.

Since the CPU examines only a sampling of the ingress IP traffic on a port, there is no guarantee that the switch will caught or prevent this type of attack.

375

Page 375
Image 375
Allied Telesis management software layer 2+ fast ethernet switches manual SET DOS Teardrop, Mirrorport