Enabling Strict Control of ACL Filtering of Fragmented Packets
For strict control of ACL filtering of
fragmented packets received on an interface, you can configure the interface to
drop
all packet fragments. To do so, apply the ip access-group frag
deny command to the interface.
This option begins dropping all fragments received by the port as soon as you enter the command. The option is especially useful if the port is receiving an unusually high rate of fragments, which can indicate a hacker attack.
In the following example, the ACL is applied to port 1/1/1.
device# configure terminal device(config)# interface ethernet 1/1/1 device(config-if-1/1/1)# ip access-group frag deny
In the following example, the ACL is applied to multiple interfaces simultaneously.
device# configure terminal device(config)# interface ethernet 1/1/15 to 1/1/20 device(config-mif-1/1/15-1/1/20)# ip access-group frag deny