ip access-group frag deny

Allows strict filtering of fragmented packets.
Syntax
ip access-group frag deny
no ip access-group frag deny
Command Default

By default, packet fragments are not dropped.

Modes

interface configuration mode

Usage Guidelines

As soon as you enter the command, the interface begins dropping all received packet fragments. The option is useful if the port is receiving an unusually high rate of fragments, which could indicate a hacker attack.

The command is not supported on LAG interfaces.

The no form of the command immediately removes packet filtering for fragments from the interface.

Examples

The following example immediately applies packet fragment filtering to port 1/1/1.

device# configure terminal
device(config)# interface ethernet 1/1/1
device(config-if-1/1/1)# ip access-group frag deny