Defense against ICMP Denial of Service Attacks on ICX 8100 and ICX 8200 Devices
To prevent DOS attacks on RUCKUS ICX 8100 and ICX 8200 devices, you can rate limit ICMP pings to the CPU. You can also drop irregular ICMP packet fragments.
Rate Limiting ICMP Control Traffic
Use the ip icmp burst-max
command as shown to limit ICMP pings to the CPU. Valid values are 20 through
10000000 kbps.
The following example limits the rate of ICMP pings to the CPU to 50 Kbps.
device# configure terminal device(config)# ip icmp burst-max 50
The command can also be used on a specific interface. The following example limits ICMP pings to the CPU to 20 kbps on port 1/2/3.
device# configure terminal device(config)# interface ethernet 1/2/3 device(config-if-e1000-1/2/3)# ip icmp burst-max 20
Dropping Suspicious ICMP Packet Fragments
Use the following command to drop irregular, suspect ICMP packet fragments in order to prevent DOS attacks.
device# configure terminal device(config)# ip icmp icmp-fragments