Denial of Service (DoS) Commands
369
OL-32830-01 Command Line Interface Reference Guide
16
switchxxxxxx(config)#
security-suite enable global-rules-only
switchxxxxxx(config)#
interface
gi1
1
switchxxxxxx(config-if)#
security-suite deny syn add any /32 any
To perform this command, DoS Prevention must be enabled in the per-interface mode.
16.5 security-suite deny syn-fin
To drop all ingressing TCP packets in which both SYN and FIN are set, use the
security-suite deny syn-fin Global Configuration mode command.
To permit TCP packets in which both SYN and FIN are set, use the no form of this
command.
Syntax
security-suite deny syn-fin
no security-suite deny syn-fin
Parameters
This command has no arguments or keywords.
Default Configuration
The feature is disabled by default.
Command Mode
Global Configuration mode
Example
The following example blocks TCP packets in which both SYN and FIN flags are
set.
switchxxxxxx(config)#
security-suite deny sin-fin
Summary of Contents for 300 Series
Page 2: ......