ip access-group frag deny
By default, packet fragments are not dropped.
interface configuration mode
multiple-interface configuration mode
As soon as you enter the command, the interface begins dropping all received packet fragments. The option is useful if the port is receiving an unusually high rate of fragments, which could indicate a hacker attack.
The command is not supported on LAG interfaces.
The no form of the command
immediately removes packet filtering for fragments from the interface.
The following example immediately applies packet fragment filtering to port 1/1/1.
device# configure terminal device(config)# interface ethernet 1/1/1 device(config-if-1/1/1)# ip access-group frag deny
| Release version | Command history |
|---|---|
| 10.0.20 | This command was modified to add the multiple-interface configuration option. |