Security-Suite Syn Protection Threshold - Cisco Sx350 Cli Manual

Hide thumbs Also See for Sx350:
Table of Contents

Advertisement

10
Denial of Service (DoS) Commands
Parameters
timeout—Defines the timeout (in seconds) by which an interface from which SYN packets are blocked
gets unblocked. Note that if a SYN attack is still active on this interface it might become blocked again.
(Range: 10-600)
Default Configuration
The default timeout is 60 seconds.
Command Mode
Global Configuration mode
User Guidelines
If the timeout is modified, the new value will be used only on interfaces which are
not currently under attack.
Example
The following example sets the TCP SYN period to 100 seconds.
security-suite syn protection recovery 100
switchxxxxxx(config)#

10.11 security-suite syn protection threshold

To set the threshold for the SYN protection feature, use the security-suite syn
protection threshold Global Configuration mode command.
To set the threshold to its default value, use the no form of this command.
Syntax
security-suite syn protection threshold syn-packet-rate
no security-suite syn protection threshold
Parameters
syn-packet-rate—defines the rate (number of packets per second) from each specific port that triggers
identification of TCP SYN attack. (Range: 20-200)
Default Configuration
The default threshold is 80pps (packets per second).
Command Mode
Global Configuration mode
277
Cisco Sx350 Ph. 2.2.5 Devices - Command Line Interface Reference Guide

Advertisement

Table of Contents
loading

Table of Contents