Enabling Strict Control of ACL Filtering of Fragmented Packets

For strict control of ACL filtering of fragmented packets received on an interface, you can configure the interface to drop all packet fragments. To do so, apply the ip access-group frag deny command to the interface. In the following example, the ACL is applied to port 1/1/1.

device# configure terminal
device(config)# interface ethernet 1/1/1
device(config-if-1/1/1)# ip access-group frag deny

This option begins dropping all fragments received by the port as soon as you enter the command. The option is especially useful if the port is receiving an unusually high rate of fragments, which can indicate a hacker attack.

Note: The ip access-group frag deny command is not supported on LAG interfaces.