Syn Filtering - Cisco SF500-24 Administration Manual

Esw2 series advanced switches
Hide thumbs Also See for SF500-24:
Table of Contents

Advertisement

20
STEP 3
STEP 4
STEP 5
STEP 1
STEP 2
STEP 3
411
To add a Martian address click Add.
Enter the parameters.
IP Version—Indicates the supported IP version. Currently, support is only
offered for IPv4.
IP Address—Enter an IP addresses to reject. The possible values are:
From Reserved List
-
list.
New IP Address
-
Mask—Enter the mask of the IP address to define a range of IP addresses to
reject. The values are:
Network Mask
-
Prefix Length
-
addresses for which Denial of Service prevention is enabled.
Click Apply. The Martian addresses are written to the Running Configuration file.

SYN Filtering

The SYN Filtering page enables filtering TCP packets that contain a SYN flag, and
are destined for one or more ports.
To define a SYN filter:
Click Security > Denial of Service Prevention > SYN Filtering.
Click Add.
Enter the parameters.
Interface—Select the interface on which the filter is defined.
IPv4 Address—Enter the IP address for which the filter is defined, or select
All Addresses.
Network Mask—Enter the network mask for which the filter is enabled in IP
address format.
TCP Port—Select the destination TCP port being filtered:
-
Known Ports—Select a port from the list.
Cisco 500 Series Stackable Managed Switch Administration Guide Release 1.3
—Select a well-known IP address from the reserved
—Enter an IP address.
—Network mask in dotted decimal format.
—Enter the prefix of the IP address to define the range of IP
Security
Denial of Service Prevention

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents