Security-Suite Syn Protection Recovery; Security-Suite Syn Protection Threshold - Cisco 220 Series Smart Plus Reference Manual

Smart plus switches command line interface
Hide thumbs Also See for 220 Series Smart Plus:
Table of Contents

Advertisement

SYN Protection Commands

security-suite syn protection recovery

security-suite syn protection recovery

security-suite syn protection threshold

Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x
To set the time period for SYN protection to block an attacked interface, use the
security-suite syn protection recovery Global Configuration mode command.
Syntax
security-suite syn protection recovery
Parameters
seconds
—The timeout in seconds by which an interface from which SYN
packets are blocked gets unblocked. Note that if a SYN attack is still active
on this interface, it may become blocked again. (Range: 10 to 600 seconds)
Default Configuration
The default timeout is 60 seconds.
Command Mode
Global Configuration mode
User Guidelines
If the timeout is modified, the new value is only used on interfaces that are not
currently under attack.
Example
The following example sets the SYN protection auto-recovery timeout to 100
seconds:
switchxxxxxx(config)# security-suite syn protection recovery 100
To set the SYN protection threshold, use the security-suite syn protection
threshold Global Configuration mode command.
Syntax
security-suite syn protection threshold
seconds
pps
34
451

Advertisement

Table of Contents
loading

Table of Contents