Filter and Firewall
Left running head:
Chapter name (automatic)
752
Beta Beta
OmniAccess 5740 Unified Services Gateway CLI Configuration Guide
Alcatel-Lucent
E
XAMPLE
ALU(config-firewall-attack-A1)# default
ALU(config-firewall-attack-A1)# default stateless
ALU(config-firewall-attack-A1)# no default
ALU(config-firewall-attack-A1)# no default stateless
You can create a “default” attack setting to check default attacks on ingress traffic
to all interfaces.
In OmniAccess 5740 USG, the default DoS attack is configured for the prevention
of all attacks and their default settings except "icmp-block-trace-route", "icmp-
router-advertisement", "icmp-redirect". These attacks too can be either
manually turned on for detection or filters can be applied to block them. The
minimum time resolution you can enter is 5 milliseconds.
Command (in F-ACM) Description
default [stateless] This command is used to configure all
the default attacks for an attack object.
• Default keyword configures all the
Default Rate Limiting attacks (i.e,
both Stateful and Stateless attacks)
• Stateless keyword configures only
the Default Non-rate Limiting (i.e.,
only Stateless attacks.)
no default [stateless] The ‘no’ command disables all the
default attacks configured for an attack
object.
Stateless keyword disables only the
stateless default attacks.