Show Security-Suite Syn Protection - Cisco Sx350 Cli Manual

Hide thumbs Also See for Sx350:
Table of Contents

Advertisement

10
279
Interface
---------------
gi1
2
Fragmented packets filtering
Interface
--------------
gi1
2

10.13 show security-suite syn protection

To display the SYN Protection feature configuration and the operational status per interface-id, including
the time of the last attack per interface, use the show security-suite syn protection
command.
Syntax
show security-suite syn protection [interface-id]
Parameters
interface-id—(Optional) Specifies an interface-ID. The interface-ID can be one of the following types:
Ethernet port of Port-Channel.
Command Mode
User EXEC mode
User Guidelines
Use the Interface-ID to display information on a specific interface.
Example
The following example displays the TCP SYN protection feature configuration and current status on all
interfaces. In this example, port gi12 is attacked but since there is a user-ACL on this port, it cannot
become blocked so its status is Reported and not Blocked and Reported.
show security-suite syn protection
switchxxxxxx#
Protection Mode: Block
Threshold: 40 Packets Per Second
Period: 100 Seconds
Interface Name
Current Status
gi11
Attacked
IP Address
--------------
176.16.23.0\24
IP Address
--------------
176.16.23.0\24
Last Attack
19:58:22.289 PDT Feb 19 2012 Blocked and Reported
Cisco Sx350 Ph. 2.2.5 Devices - Command Line Interface Reference Guide
Denial of Service (DoS) Commands
switchxxxxxx>

Advertisement

Table of Contents
loading

Table of Contents