Disabling The Icmp Security Checks On An Interface - Cisco 4700M Configuration Manual

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Chapter 4
Configuring TCP/IP Normalization and IP Reassembly Parameters

Disabling the ICMP Security Checks on an Interface

Caution
OL-16202-01
The syntax of this command is as follows:
no normalization
For example, to disable TCP normalization on interface VLAN 100, enter:
host1/C1(config)# interface vlan 100
host1/C1(config-if)# no normalization
To reenable TCP normalization, enter:
host1/C1(config-if)# normalization
The ACE provides several ICMP security checks by matching ICMP reply packets
with request packets and using mismatched packets to detect attacks. Also, the
ACE forwards ICMP error packets only if a connection record exists pertaining to
the flow for which the error packet was received. By default, the ACE ICMP
security checks are enabled.
To disable the ICMP security checks, use the no icmp-guard command in
interface mode. Use this command as part of an overall strategy to operate the
ACE as a pure server load balancer. For details, see Chapter 1, Overview, in the
Cisco 4700 Series Application Control Engine Appliance Server Load-Balancing
Configuration Guide.
The syntax of this command is as follows:
no icmp-guard
Disabling the ACE ICMP security checks may expose your ACE and your data
center to potential security risks. After you enter the no icmp-guard command,
the ACE no longer performs NAT translations on the ICMP header and payload in
error packets, which potentially can reveal real host IP addresses to attackers.
For example, to disable ICMP security checks on interface VLAN 100, enter:
host1/C1(config)# interface vlan 100
host1/C1(config-if)# no icmp-guard
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
Configuring Interface Normalization Parameters
4-35

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents