< Home

firewall defend large-icmp enable

Function

The firewall defend large-icmp enable command enables the large ICMP packet attack defense.

The undo firewall defend large-icmp enable command disables the large ICMP packet attack defense.

Format

firewall defend large-icmp enable

undo firewall defend large-icmp enable

Parameters

None

Views

System view

Default Level

2: Configuration level

Usage Guidelines

By default, the large ICMP packet attack defense is disabled.

The maximum length of allowed ICMP packets can be configured as required. When the actual ICMP packet length exceeds the value, the device considers that the large ICMP packet attack takes place, discards the packet, and reports an attack log.

Example

# Enable the large ICMP packet attack defense.

<sysname> system-view
[sysname] firewall defend large-icmp enable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >