SROS Command Line Interface Reference Guide

Global Configuration Mode Command Set

 

 

ip firewall check winnuke

Use the ip firewall check winnuke command to enable the Secure Router OS stateful inspection firewall to discard all Out of Band (OOB) data (to protect against WinNuke attacks). Use the no form of this command to disable this feature.

Note

The Secure Router OS security features must be enabled (using the ip firewall command)

 

for the stateful inspection firewall to be activated.

 

 

Syntax Description

No subcommands.

Default Values

All Secure Router OS security features are disabled by default until the ip firewall command is issued at the Global Configuration prompt. Issuing the ip firewall command enables the WinNuke check.

Command Modes

(config)#

Global Configuration Mode

Functional Notes

WinNuke attack is a well-known denial of service attack on hosts running Microsoft Windows® operating systems. An intruder sends Out of Band (OOB) data over an established connection to a Windows user. Windows cannot properly handle the OOB data and the host reacts unpredictably. Normal shut-down of the hosts will generally return all functionality. Using the ip firewall check winnuke command configures the Secure Router OS stateful inspection firewall to filter all OOB data to prevent network problems.

Usage Examples

The following example enables the firewall to filter all OOB data:

(config)#ip firewall check winnuke

5991-2114

© Copyright 2005 Hewlett-Packard Development Company, L.P.

281

Page 281
Image 281
HP 7000 dl Router manual Ip firewall check winnuke, Config#ip firewall check winnuke