Defense against ICMP Denial of Service Attacks on ICX 8100 and ICX 8200 Devices

To prevent DOS attacks on RUCKUS ICX 8100 and ICX 8200 devices, you can rate limit ICMP pings to the CPU. You can also drop irregular ICMP packet fragments.

Rate Limiting ICMP Control Traffic

Use the ip icmp burst-max command as shown to limit ICMP pings to the CPU. Valid values are 20 through 10000000 kbps.

The following example limits the rate of ICMP pings to the CPU to 50 Kbps.

device# configure terminal
device(config)# ip icmp burst-max 50

The command can also be used on a specific interface. The following example limits ICMP pings to the CPU to 20 kbps on port 1/2/3.

device# configure terminal
device(config)# interface ethernet 1/2/3
device(config-if-e1000-1/2/3)# ip icmp burst-max 20

Dropping Suspicious ICMP Packet Fragments

Use the following command to drop irregular, suspect ICMP packet fragments in order to prevent DOS attacks.

device# configure terminal
device(config)# ip icmp icmp-fragments