User Manual - Page 56

For GC728XP-100NAS.

Loading ...
Loading ...
Loading ...
Configure System Information
56
Insight Managed 28-Port and 52-Port Gigabit Ethernet Smart Cloud Switches
Configure Denial of Service
The Denial of Service Configuration page allows you to select which types of DoS attacks the
switch monitors and blocks.
To configure individual DoS settings:
1. Connect your computer to the same network as the switch.
You can use a WiFi or wired connection to connect your computer to the network, or
connect directly to a switch that is off-network using an Ethernet cable.
2. Launch a web browser.
3. In the address field of your web browser, enter the IP address of the switch.
If you do not know the IP address of the switch, see Access the Switch on page 13.
The login window opens.
4. Enter the switch’s password in the password field.
The default password is password. If you added the switch to a network on the Insight
app before and you did not yet change the password through the local browser interface,
enter your Insight network password.
The System Information page displays.
5. Select System > Management > Denial of Service > Denial of Service Configuration.
The Denial of Service Configuration page displays.
6. Select the types of DoS attacks for the switch to monitor and block and configure any
associated values:
Denial of Service Min TCP Header Size. Specify the minimum TCP header size
allowed. If DoS TCP Fragment is enabled, the switch drops packets with a TCP
header smaller than the configured value.
Denial of Service ICMPv4. Enabling ICMPv4 DoS prevention causes the switch to
drop ICMPv4 packets with a type set to ECHO_REQ (ping) and a size greater than
the configured ICMPv4 packet size.
Denial of Service Max ICMPv4 Packet Size. Specify the maximum ICMPv4 packet
size allowed. If ICMPv4 DoS prevention is enabled, the switch drops IPv4 ICMP ping
packets with a size greater than the configured value.
Denial of Service ICMPv6. Enabling ICMPv6 DoS prevention causes the switch to
drop ICMPv6 packets with a type set to ECHO_REQ (ping) and a size greater than
the configured ICMPv6 packet size.
Denial of Service Max ICMPv6 Packet Size. Specify the maximum IPv6 ICMP
packet size allowed. If ICMPv6 DoS prevention is enabled, the switch drops IPv6
ICMP ping packets with a size greater than the configured maximum ICMPv6 packet
size.
Denial of Service First Fragment. Enabling First Fragment DoS prevention causes
the switch to check DoS options on first fragment IP packets when the switch receives
fragmented IP packets. Otherwise, the switch ignores the first fragment IP packages.
Loading ...
Loading ...
Loading ...