OSPF
The following table lists auto rules that are used to mitigate OSPF attacks on your advanced appliance when OSPF is not in use. For information about the parameters, see Overview of Packet Flow.
Rule ID | Rule Type | Rule Name | Description | Enable Condition | Parameters | Comments |
---|---|---|---|---|---|---|
130900300 | Auto | DROP OSPF unexpected | This rule drops unexpected OSPF packets. | This rule takes effect when OSPF service on this member is NOT configured. | Events per second (default=1) | Default drop rule for all packets on the OSPF service port. |
130900400 | Auto | RATELIMIT PASS OSPF multicast | This rule passes OSPF IPv4 multicast packets if the packet rate is less than the Packets per second value. If any source IP sends packets over this value, the appliance allows traffic up to the rate limit and then blocks traffic from this source IP for the remainder of the Drop interval. | This rule takes effect when OSPF service on this member is configured for IPv4. | Packets per second (default=100) Drop Interval (default=60 sec) Rate algorithm (default = rate limiting) Events per second (default=1) | |
130900500 | Auto | RATELIMIT PASS OSPF IPv6 multicast | This rule passes OSPF IPv6 multicast packets if the packet rate is less than the Packets per second value. If any source IP sends packets over this value, the appliance allows traffic up to the rate limit and then blocks traffic from this source IP for the remainder of the Drop interval. | This rule takes effect when OSPF service on this member is configured for IPv6. | Packets per second (default=100) Drop Interval (default=60 sec) Rate algorithm (default = rate limiting) Events per second (default=1) | |
130900600 | Auto | RATELIMIT PASS OSPF | This rule passes OSPF packets if the packet rate is less than the Packets per second value. If any source IP sends packets over this value, the appliance allows traffic up to the rate limit and then blocks traffic from this source IP for the remainder of the Drop interval. | This rule takes effect when OSPF service on this member is configured. | Packets per second (default=50) Drop Interval (default=10 sec) Rate algorithm (default = rate limiting) Events per second (default=1) | This rule works for both IPv4 and IPv6. |