< Home

firewall defend smurf enable

Function

The firewall defend smurf enable command enables the Smurf attack defense.

The undo firewall defend smurf enable command disables the Smurf attack defense.

Format

firewall defend smurf enable

undo firewall defend smurf enable

Parameters

None

Views

System view

Default Level

2: Configuration level

Usage Guidelines

By default, the Smurf attack defense is disabled.

After Smurf attack defense is enabled, the FW checks whether the host portion of the destination IP address of ICMP request packets is a multicast IP address, all 1s, or all 0s. If so, the packet is discarded.

Example

# Enable the Smurf attack defense.

<sysname> system-view
[sysname] firewall defend smurf enable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >