для Cisco Cisco Firepower 4120 Security Appliance
Table 178: BDoS Footprint Bypass Fields and Values for UDP, ICMP, and IGMP Controllers (cont.)
Controller
Field
Default
Status
Status
Default Value or
“N/A”
“N/A”
1
Remark
UDP
ICMP
ICMP
frag-offset-ipv6
2
Accept
0,181
Indicates where this IPv6 fragment belongs in the
datagram. The IPv6 fragment offset is measured in units of
8 bytes (64 bits).
UDP
ICMP
ICMP
flow-label
2
Accept
0,181
Used by a source to label those products for which it
requests special handling by the IPv6 router. The flow is
uniquely identified by the combination of a Source address
and a non-zero flow label.
UDP
ICMP
IGMP
ICMP
IGMP
source-ip
Accept
N/A
The source IP address of the attack.
UDP
ICMP
ICMP
source-ip-ipv6
2
Accept
N/A
The source IPv6 address of the attack.
UDP
ICMP
IGMP
ICMP
IGMP
tos
Accept
N/A
The type of Service value from the IP packet
header.
UDP
ICMP
IGMP
ICMP
IGMP
packet-size
Accept
For UDP and IGMP: N/A
For ICMP: 74
For ICMP: 74
The size of the packet in bytes, including data-link header.
UDP
ICMP
ICMP
packet-size-ipv6
2
Accept
For UDP: N/A
For ICMP: 118
For ICMP: 118
The size of the IPv6 packet in bytes, including data- link
header.
UDP
destination-port
Accept
N/A
The destination port from the packet header.
UDP
ICMP
IGMP
ICMP
IGMP
destination-ip
Accept
N/A
The destination IP address.
UDP
ICMP
ICMP
destination-ip-ipv6
2
Accept
N/A
The destination IPv6 address.
© 2016 Cisco | Radware. All rights reserved. This document is Cisco Public.
Page 234 of 281