Security Commands
359
ProSAFE M7100 Managed Switches
dos-control tcpfinurgpsh
This command enables TCP FIN and URG and PSH and SEQ=0 checking Denial of Service
protections. If the mode is enabled, Denial of Service prevention is active for this type of attack.
If packets ingress having TCP FIN, URG, and PSH all set and TCP Sequence Number set to 0, the
packets will be dropped if the mode is enabled.
no dos-control tcpfinurgpsh
This command disables TCP FIN and URG and PSH and SEQ=0 checking Denial of Service
pro
tections.
dos-control icmpv4
This command enables the maximum ICMPv4 packet size for denial of service protections. If the
mode is enabled, denial of service prevention is active for this type of attack. If ingress ICMPv4
echo request (ping) packets have a size greater than the configured value, the packets are
dropped if the mode is enabled.
no dos-control icmpv4
This command disables the maximum ICMPv4 packet size for denial of service protection.
Default disabled
Format dos-control tcpfinurgpsh
Mode Global Config
Format no dos-control tcpfinurgpsh
Mode Global Config
Default • disabled
• The maximum ICMPv4 pack
e
t size for denial of service protection is 512 Bytes.
Format dos-control icmpv4 <0-16376>
Mode Global Config
Format no dos-control icmpv4
Mode Global Config