![Cisco Sx350 Cli Manual Download Page 276](http://html.mh-extra.com/html/cisco/sx350/sx350_cli-manual_2609320276.webp)
Denial of Service (DoS) Commands
275
Cisco Sx350 Ph. 2.2.5 Devices - Command Line Interface Reference Guide
10
switchxxxxxx(config)#
security-suite enable global-rules-only
switchxxxxxx(config)#
interface
gi1
1
switchxxxxxx(config-if)#
security-suite dos syn-attack
199 any /10
To perform this command, DoS Prevention must be enabled in the per-interface mode.
Example 2—The following example enables the security suite feature globally and
on interfaces. The security-suite command succeeds on the port.
switchxxxxxx(config)#
security-suite enable
switchxxxxxx(config)#
interface
gi1
1
switchxxxxxx(config-if)#
security-suite dos syn-attack 199 any /10
switchxxxxxx(config-if)#
10.9 security-suite syn protection mode
To set the TCP SYN protection mode, use the security-suite syn protection mode
Global Configuration mode command.
To set the TCP SYN protection mode to default, use the no form of this command.
Syntax
security-suite syn protection mode {disabled | report | block}
no security-suite syn protection mode
Parameters
•
disabled—Feature is disabled
•
report—Feature reports about TCP SYN traffic per port (including
rate-limited SYSLOG message when an attack is identified)
•
block—TCP SYN traffic from attacking ports destined to the local system is
blocked, and a rate-limited SYSLOG message (one per minute) is generated
Default Configuration
The default mode is block.
Command Mode
Global Configuration mode
Summary of Contents for Sx350
Page 1: ...Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide CLI GUIDE ...
Page 26: ...25 Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 1 ...
Page 237: ...CDP Commands Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 236 8 ...
Page 975: ...RADIUS Commands Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 974 48 ...