Artificial intelligent assistant

Why do we need to use "Service Disable-ip-fast-frag" command in Cisco Router ? What is the benefit by Disabling " IP particle-based fast fragmentation " service on Cisco routers ? Thanks in Advance, Sajith

So according to a Mark Malone, CCIE on Cisco support, the command is used to turn off the security feature to prevent fragmentation attacks that can occur on interfaces for DDoS (it's turned on by default).

IP fragmentation attacks are a common form of denial of service attack, in which the perpetrator overloads a network by exploiting datagram fragmentation mechanisms.

So remember when using `service disable-ip-fast-frag` your router could be vulnerable to fragmentation attacks.

xcX3v84RxoQ-4GxG32940ukFUIEgYdPy 86bb25b4835eddc1dddb60a691af7cca