< Home

firewall defend tracert enable

Function

The firewall defend tracert enable command enables the Tracert packet attack defense.

The undo firewall defend tracert enable command disables the Tracert packet attack defense.

Format

firewall defend tracert enable

undo firewall defend tracert enable

Parameters

None

Views

System view

Default Level

2: Configuration level

Usage Guidelines

By default, the Tracert packet attack defense is disabled.

After the Tracert packet attack defense is configured, a FW discards ICMP timeout packets, UDP timeout packets, or destination port unreachable packets. In this way, attackers cannot discover the network topology using commands, such as Tracert.

Example

# Enable the Tracert packet attack defense function.

<sysname> system-view
[sysname] firewall defend tracert enable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >