< Home

firewall defend teardrop enable

Function

The firewall defend teardrop enable command enables the Teardrop attack defense.

The undo firewall defend teardrop enable command disables the Teardrop attack defense.

Format

firewall defend teardrop enable

undo firewall defend teardrop enable

Parameters

None

Views

System view

Default Level

2: Configuration level

Usage Guidelines

By default, the Teardrop attack defense is disabled.

After the Teardrop attack defense is enabled, a FW analyzes the received fragment packets to check whether the offsets of the packets are correct. If the offsets are incorrect, the device discards the packets and records an attack log.

Example

# Enable the Teardrop attack defense.

<sysname> system-view
[sysname] firewall defend teardrop enable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >