Switching Commands
214
ProSafe Managed Switch
dos-control sipdip
This command enables Source IP address = Destination IP address (SIP=DIP) Denial of
Service protection. If the mode is enabled, Denial of Service prevention is active for this type
of attack. If packets ingress with SIP=DIP, the packets will be dropped if the mode is enabled.
Default
Format dos-control sipdip
Mode
no dos-control sipdip
This command disables Source IP address = Destination IP address (SIP=DIP) Denial of
Service prevention.
Format no dos-control sipdip
Mode
dos-control firstfrag
This command enables Minimum TCP Header Size Denial of Service protection. If the mode
is enabled, Denial of Service prevention is active for this type of attack. If packets ingress
having a TCP Header Size smaller then the configured value, the packets will be dropped if
the mode is enabled.The default is disabled. If you enable dos-control firstfrag, but do not
provide a Minimum TCP Header Size, the system sets that value to 20.
Default
Format dos-control firstfrag [<0-255>]
Mode
no dos-control firstfrag
This command sets Minimum TCP Header Size Denial of Service protection to the default
value of disabled.
Format no dos-control firstfrag
Mode
disabled
Global Config
Global Config
disabled <20>
Global Config
Global Config