Packet Fragmentation Supported by ACLs
The device can filter fragmented packets by matching fragmented packets with Layer 3 filtering rules.
If fragment is not specified in an ACL rule, the device matches non-initial fragmented packets in addition to non-fragmented packets and initial-fragmented packets (they are processed using the same method). However, if an ACL rule contains a Layer 4 port number, the switch does not match fragmented packets.
If fragment is specified in the ACL rule, the device only matches non-initial fragmented packets.
When attackers construct fragmented packets to attack the network, you can specify fragment in an ACL rule to enable the device to filter non-initial fragmented packets only. This prevents the device from filtering other non-fragmented packets, ensuring normal service transmission.