ip access-group frag deny
Allows strict filtering of fragmented
packets.
Command Default
By default, packet fragments are not dropped.
Modes
interface configuration mode
Usage Guidelines
As soon as you enter the command, the interface begins dropping all received packet fragments. The option is useful if the port is receiving an unusually high rate of fragments, which could indicate a hacker attack.
The command is not supported on LAG interfaces.
The no form of the command
immediately removes packet filtering for fragments from the interface.