Vigor2860 Series User’s Guide
587
THRESHOLD
It means the packet rate (packet/second) that a flooding
attack will be detected. Set a value larger than 20.
TIMEOUT
It means the time (seconds) that a flooding attack will be
blocked. Set a value larger than 5.
-a
It means to enable the defense function for all attacks
listed in ATTACK_0.
-e
It means to enable defense function for a specific
attack(s).
ATTACK_0
It means to specify a name of the following attacks:
ip_option, tcp_flag, land, teardrop, smurf, pingofdeath,
traceroute, icmp_frag, syn_frag, unknow_proto, fraggle.
-d
It means to disable the defense function for a specific
attack(s).
Example
>dos –A
The Dos Defense system is Activated
>dos –s synflood 50 10
Synflood is enabled! Threshold=50 <pke/sec> timeout=10 <pke/sec>