Show Security-Suite Syn Protection - Cisco 300 Series Cli Manual

Stackable managed switches
Hide thumbs Also See for 300 Series:
Table of Contents

Advertisement

Denial of Service (DoS) Commands
OL-32830-01 Command Line Interface Reference Guide
Interface
---------------
gi1
2
Fragmented packets filtering
Interface
--------------
gi1
2

16.13 show security-suite syn protection

To display the SYN Protection feature configuration and the operational status per interface-id, including
the time of the last attack per interface, use the show security-suite syn protection
command.
Syntax
show security-suite syn protection [interface-id]
Parameters
interface-id—(Optional) Specifies an interface-ID. The interface-ID can be one of the following types:
Ethernet port of Port-Channel.
Command Mode
User EXEC mode
User Guidelines
Use the Interface-ID to display information on a specific interface.
Example
The following example displays the TCP SYN protection feature configuration and current status on all
interfaces. In this example, port gi12 is attacked but since there is a user-ACL on this port, it cannot
become blocked so its status is Reported and not Blocked and Reported.
show security-suite syn protection
switchxxxxxx#
Protection Mode: Block
Threshold: 40 Packets Per Second
Period: 100 Seconds
Interface
Current
Name
Status
----------------
------------------
IP Address
--------------
176.16.23.0\24
IP Address
--------------
176.16.23.0\24
Last
Attack
--------------------------------------------------------------------------
16
switchxxxxxx>
378

Advertisement

Table of Contents
loading

Table of Contents