< Home

Configuring Tracert Packet Attack Defense

In a Tracert packet attack, an attacker discovers the path between the source host and the destination host by using the replied ICMP timeout packet when TTL is 0 and the ICMP port unreachable packet replied by the destination.

Context

In a Tracert attack, the attacker discovers the path between the source host and the destination according to the returned ICMP timeout packet when the TTL value is 0 and the ICMP port unreachable packet returned from the destination. The attacker can probe the network structure.

After Tracert packet attack defense is configured, the device discards ICMP or UDP timeout packets, or destination port unreachable packets.

Procedure

  1. In the user view, access the system view.

    system-view

  2. Enable Tracert packet attack defense.

    firewall defend tracert enable

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >