处理路由器%IP_VFR-4-FRAG_TABLE_OVERFLOW报错 单位路由器经常提示如下错误,并且网络速度明显降低: %IP_VFR-4-FRAG_TABLE_OVERFLOW: FastEthernet0: the fragment table has reached its maximum threshold 16
经
处理路由器%IP_VFR-4-FRAG_TABLE_OVERFLOW报错 单位路由器经常提示如下错误,并且网络速度明显降低: %IP_VFR-4-FRAG_TABLE_OVERFLOW: FastEthernet0: the fragment table has reached its maximum threshold 16
经查,是受到了网络碎片攻击。采取以下措施,效果明显: www.zhishiwu.com 1. 在端口提高包重组能力: int f0 ip virtual-reassembly max-reassemblies 1024 2. 在端口加acl拦截攻击包: int f0 ip access-group 120 in ip access-group 120 out access-list 120 deny ip any any fragments permit ip any any 从此cpu利用率恢复正常,网速也得到恢复。