Security-Suite Deny Syn-Fin - Cisco 300 Series Cli Manual

Stackable managed switches
Hide thumbs Also See for 300 Series:
Table of Contents

Advertisement

16
369
switchxxxxxx(config)#
switchxxxxxx(config)#
switchxxxxxx(config-if)#
To perform this command, DoS Prevention must be enabled in the per-interface mode.

16.5 security-suite deny syn-fin

To drop all ingressing TCP packets in which both SYN and FIN are set, use the
security-suite deny syn-fin Global Configuration mode command.
To permit TCP packets in which both SYN and FIN are set, use the no form of this
command.
Syntax
security-suite deny syn-fin
no security-suite deny syn-fin
Parameters
This command has no arguments or keywords.
Default Configuration
The feature is disabled by default.
Command Mode
Global Configuration mode
Example
The following example blocks TCP packets in which both SYN and FIN flags are
set.
switchxxxxxx(config)#
security-suite enable global-rules-only
interface gi11
security-suite deny syn add any /32 any
security-suite deny sin-fin
OL-32830-01 Command Line Interface Reference Guide
Denial of Service (DoS) Commands

Advertisement

Table of Contents
loading

Table of Contents