The firewall defend smurf enable command enables the Smurf attack defense.
The undo firewall defend smurf enable command disables the Smurf attack defense.
Format
firewalldefendsmurfenable
undofirewalldefendsmurfenable
Parameters
None
Views
System view
Default Level
2: Configuration level
Usage Guidelines
By default, the Smurf attack defense is disabled.
After Smurf attack defense is enabled, the FW checks whether the host portion of the destination IP address of ICMP request packets is a multicast IP address, all 1s, or all 0s. If so, the packet is discarded.