![Cisco 350XG series Administration Manual Download Page 452](http://html.mh-extra.com/html/cisco/350xg-series/350xg-series_administration-manual_67491452.webp)
Security
Denial of Service Prevention
Cisco 350XG & 550XG Series 10G Stackable Managed Switches
438
19
SYN Filtering
The SYN Filtering page
enables
filtering TCP packets that contain a SYN flag, and
are destined for one or more ports.
To define a SYN filter:
STEP 1
Click
Security
>
Denial of Service Prevention
>
SYN Filtering
.
STEP 2
Click
Add
.
STEP 3
Enter the parameters.
•
Interface
—Select the interface on which the filter is defined.
•
IPv4 Address
—Enter the IP address for which the filter is defined, or select
All Addresses
.
•
Network Mask
—Enter the network mask for which the filter is enabled in IP
address format.
•
TCP Port
—Select the destination TCP port being filtered:
-
Known Ports
—Select a port from the list.
-
User Defined
—Enter a port number.
-
All Ports
—Select to indicate that all ports are filtered.
STEP 4
Click
Apply
. The SYN filter is defined, and the Running Configuration file is
updated.
SYN Rate Protection
The SYN Rate Protection page
enables
limiting the number of SYN packets
received on the ingress port. This can mitigate the effect of a SYN flood against
servers, by rate limiting the number of new connections opened to handle
packets.
To define SYN rate protection:
STEP 1
Click
Security
>
Denial of Service Prevention
>
SYN Rate Protection
.
This page appears the SYN rate protection currently defined per interface.
STEP 2
Click
Add
.