ip icmp attack-rate
ip icmp attack-rate
burst-normal
threshold-value
burst-max
max-value
lockup
timeno ip icmp attack-rate
burst-normal
threshold-value
burst-max
max-value
lockup
timeNo threshold values for ICMP packets are configured. It is recommended to configure ICMP protection for any switch vulnerable to these attacks.
Global configuration mode
Interface configuration sub-mode
VLAN configuration sub-mode
You can configure the device to drop ICMP packets when excessive number of packets are encountered as is the case when the device is the victim of a Smurf attack. You can set threshold values for ICMP packets that are targeted at the router itself or that pass through an interface, and drop them when the thresholds are exceeded.
The
no form of the command removes the configured threshold values.
The following example sets threshold values for ICMP packets targeted at the router.
device# configure terminal device(config)# ip icmp attack-rate burst-normal 2000 burst-max 2500 lockup 300
The following example sets threshold values for ICMP packets received on interface 3/1/1.
device# configure terminal device(config)# interface ethernet 3/1/1 device(config-if-e1000-3/1/1)# ip icmp attack-rate burst-normal 2000 burst-max 2500 lockup 300