Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Rate-limiting on serial interfaces to prevent common DOS attacks

Status
Not open for further replies.

rainman

ISP
Mar 22, 2001
186
US
Does anyone have any good suggestions on ways to implement DOS protection by enabling rate-limiting features on serial interfaces? Also by enabling such a feature what type of burden would I expect to be placed on the router's processor? Any suggestions?


Rainman
 
rain - from what i understand if you're not using firewall/nat'ting then there are a couple of things you can do. Anyone feel free to correct me if i'm wrong. First, make sure you have "no ip directed-broadcast" conf. on the interface and in global conf specify "no ip source-route" . Also, it is a v. good idea to simply put an Access-list denying any icmp traffic from the outside world or you could configure QoS to put ICMP traffic at the lowest priority.

"access-list 101 permit icmp yourmachine any" (you'll prob. want some admin machines to be able to ping)
"access-list 101 deny icmp any any"

hope this helps.

jason
 
basically, when ip redirects is enabled, it is allowed to forward received packets back out the interface in which is was received. there are instances where this needs to be done (ie HSRP), but unless you have to, its a bad idea to leave this enabled.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top