fwaccel dos drop_frags
Description
The "fwaccel dos drop_frags
" (for IPv4) and "fwaccel6 dos drop_frags
" (for IPv6) commands control the drop of IP Fragments in SecureXL.
|
Important:
|
Syntax
|
Parameters
Parameter |
Description |
||
---|---|---|---|
No Parameters |
Shows the applicable built-in usage. |
||
|
Shows the applicable built-in usage. |
||
|
Adds an IP address of a host or a network to a persistent "Allow List", so this IP address is not affected by the DoS / Rate Limiting protection:
|
||
|
Shows the current configuration. |
||
|
Enables (
|
||
|
Enables (
|
||
|
Enables (
|
||
|
Enables ( In the monitor-only mode you can test the drops of IP Fragments without blocking the traffic. The Security Gateway does not block traffic, but still generates a log.
|
||
|
Configures the maximum number of logs per second for packet drops. When DoS / Rate Limiting blocks many packets, it can be important to limit the maximum number of the drop logs that the Security Gateway generates per second.
|
Example from a non-VSX Gateway