2.4 Disable the IP Unreachable Function

Information

The ROSNG system product no longer uses U to respond to the icmp request.

Use icmp unreachable and change the source address to the address of the attacking device to prevent smurf attack

Solution

ZXR10#config terminal
ZXR10 (config)#icmp-config
ZXR10 (config-icmp)# interface fei-0/2/1/7
ZXR10 (config-icmp-if)#no ip unreachable
ZXR10 (config-icmp-if)#no ipv6 unreachable
ZXR10 (config-icmp-if)#end

See Also

https://support.zte.com.cn/support/doccenter/DocumentProductHandBookDetail.aspx?sid=102&id=30768582&type=docfeedback

Item Details

Audit Name: Tenable ZTE ROSNG

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: ZTE_ROSNG

Control ID: 1fce91b1dfe2728879b119252c2d0db47327182244f071d44f07c6c7b685022b