07-31-2002 03:58 AM - edited 02-20-2020 10:11 PM
Hi,
my question is:
- How PIX works normally with fragmented packets? reley these, blocks, discards or reassebles?
- And what changes if I type: "sysopt security fragguard"?
THX,
Graz
07-31-2002 10:14 PM
Following link explains your queries regarding default action for fragmented packets arriving on PIX.
In order to manage fragmented packets arriving on PIX which are legitimate, you need to configure the 'fragment' command on PIX.
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_62/cmdref/df.htm#xtocid15
Using the 'sysopt security fragguard' protects the PIX against IP fragment style attacks recommended in RFC 1858 against the many others: eg teardrop, land, etc.
HTH
R/Yusuf
07-31-2002 10:47 PM
Thanks!
Graz.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide