Chapter 34: Syn Protection Commands; Security-Suite Syn Protection Mode - Cisco 220 Series Smart Plus Reference Manual

Smart plus switches command line interface
Hide thumbs Also See for 220 Series Smart Plus:
Table of Contents

Advertisement

SYN Protection Commands

security-suite syn protection mode

SYN Protection Commands
security-suite syn protection mode
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x
To protect TCP SYN attacks and set its protection mode, use the security-suite syn
protection mode Global Configuration mode command.
Syntax
security-suite syn protection mode {block | disabled | report}
Parameters
block—Blocks the TCP SYN traffic from attacking ports destined to the
local system, and generates a rate-limited syslog message.
disabled— Disables the SYN protection feature.
report—Reports for the SYN protection feature about TCP SYN traffic per
port (including rate-limited syslog message when an attack is identified).
Default Configuration
The default mode is block.
Command Mode
Global Configuration mode
Example
The following example enables SYN protection in block mode on the switch:
switchxxxxxx(config)# security-suite syn protection mode block
34
450

Advertisement

Table of Contents
loading

Table of Contents