
Global Configuration Mode Command Set Command Reference Guide
198 © 2003 ADTRAN, Inc. 61950860L1-35D
ip firewall check winnuke
Use the ip firewall check winnuke command to enable the ADTRAN OS stateful inspection firewall to
discard all Out of Band (OOB) data (to protect against WinNuke attacks). Use the no form of this
command to disable this feature.
The ADTRAN OS security features must be enabled (using the ip firewall command) for
the stateful inspection firewall to be activated.
Syntax Description
No subcommands
Default Values
All ADTRAN OS security features are disabled by default until the ip firewall command is issued at the
the Global Configuration prompt. Issuing the ip firewall command enables the WinNuke check.
Command Modes
(config)# Global Configuration Mode
Command History
Release 2.1 Command was introduced
Functional Notes
WinNuke attack is a well-known denial of service attack on hosts running Windows
®
operating systems. An
intruder sends Out of Band (OOB) data over an established connection to a Windows user. Windows cannot
properly handle the OOB data and the host reacts unpredictably. Normal shut-down of the hosts will generally
return all functionality. Using the
ip firewall check winnuke
command configures the ADTRAN OS stateful
inspection firewall to filter all OOB data to prevent network problems.
Usage Examples
The following example enables the firewall to filter all OOB data:
(config)#
ip firewall check winnuke
Kommentare zu diesen Handbüchern