Directed Broadcast Control

Attackers sometimes use directed broadcast capabilities to start attacks such as a smurf attack. (Chapter 21, “Using Access Control Lists Effectively,” describes how smurf attacks work.) Directed broadcast allows packets to be broadcast to all the machines on the subnet directly attached to a router. This can be dangerous, because it can lead to packet floods on the network.

To disable this feature on routers, configure the following command on individual interfaces on the router:

						no ip directed-broadcast
					

Also see Chapter 21 for additional methods of controlling such floods.

Get Network Security Principles and Practices now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.