Example: Blocking Fragmented ICMP Packets (CLI)

The following example shows how to configure the icmp-fragment screen to block fragmented ICMP packets originating from the zone security zone.

To block fragmented ICMP packets:

  1. Configure the icmp-fragment screen:

    user@host# set security screen ids-option icmp-fragment icmp fragment
  2. Configure the zone security zone:

    user@host# set security zones security-zone zone screen icmp-fragment

Related Topics