< Home

Configuring Attack Defense Against IP Packets with the Timestamp

Generally, an IP timestamp option is to diagnose faults on network paths, but may also be utilized by malicious attackers to probe the network structure.

Context

The IP routing technology provides the timestamp option, which records the route and time that an IP packet takes from the source IP address to the destination IP address. The timestamp option is a list of routers that process the IP packet. It is generally used for fault diagnosis of network paths but may also be used by malicious attackers to probe the network structure.

After defense against attacks through IP packets with the timestamp is enabled, the device checks whether incoming packets contain the timestamp option. If yes, the packets are discarded and attacks are logged.

Procedure

  1. In the user view, access the system view.

    system-view

  2. Enable attack defense against IP packets with the timestamp.

    firewall defend time-stamp enable

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic