IP Fragment Attack

Configure the IP Frag Guard feature with the sysopt security fragguard command on the PIX.

This feature enforces two security checks:

First, each noninitial IP fragment is required to be associated with an already seen valid initial IP fragment.

Second, IP fragments are rated to 100 full IP fragmented packets per second to each internal host.

