Avoiding Being a Victim in a Smurf Attack
You can configure the RUCKUS device to drop ICMP packets when excessive numbers are encountered as is the case when the device is the victim of a Smurf attack. You can set threshold values for ICMP packets that are targeted at the router itself or that pass through an interface and drop them when the thresholds are exceeded.
Note: ICX 8200 and ICX 8100 devices do not support the
ip icmp attack-rate
burst-normal burst-max command. Refer to Defense against ICMP Denial of Service Attacks
on ICX 8100 and ICX 8200 Devices for
information on available ICMP DDOS options for ICX 8100 and ICX 8200
devices.The number of incoming ICMP packets is measured and compared to the threshold values as follows:
- If the number of ICMP packets exceeds the burst-normal value, the excess ICMP packets are dropped.
- If the number of ICMP packets exceeds the burst-max value, all ICMP packets are dropped for the number of seconds specified by the lockup value. When the lockup period expires, the packet counter is reset, and measurement is restarted.
Note: The
burst-normal value parameter can be from 20 through 10,000,000 Kbps. The
burst-max value parameter can be from 20 through 10,000,000 Kbps. The
lockup parameter can be from 1 through 10,000 seconds. This command is supported on Ethernet
and Layer 3 interfaces.