The configuration shown in the exhibit is used to disable IP directed-broadcasts on a specific interface of a network device. This is typically done to mitigate smurf attacks, which involve sending a large amount of ICMP echo (ping) traffic to IP broadcast addresses, all having a spoofed source address of the victim’s IP. By disabling IP directed-broadcasts, the network device will not forward packets that are sent to broadcast addresses, thus mitigating this type of DDoS attack. References: Implementing and Operating Cisco Service Provider Network Core Technologies (SPCOR) - Module on Security in the Service Provider Network
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit