426
Default
SYN flood attack protection is disabled.
Views
Attack protection policy view
Default command level
2: System level
Examples
# Enable SYN flood attack protection in attack protection policy 1.
<Sysname> system-view
[Sysname] attack-defense policy 1
[Sysname-attack-defense-policy-1] defense syn-flood enable
Related commands
•
defense
syn-flood
•
display attack-defense policy
defense syn-flood ip
Use
defense syn-flood ip
to configure the action and silence thresholds for SYN flood attack
protection of a specific IP address.
Use
undo defense syn-flood
ip
to remove the configuration.
Syntax
defense syn-flood ip
ip-address
rate-threshold high
rate-number
[
low
rate-number
]
undo defense syn-flood ip
ip-address
[
rate-threshold
]
Default
No SYN flood attack protection thresholds are configured for an IP address.
Views
Attack protection policy view
Default command level
2: System level
Parameters
ip-address
: IP address to be protected. This IP address cannot be a broadcast address, 127.0.0.0/8,
a class D address, or a class E address.
high
rate-number
: Sets the action threshold for SYN flood attack protection of the specified IP
address. The
rate-number
argument indicates the number of SYN packets sent to the specified IP
address per second and is in the range of 1 to 64000. With SYN flood attack protection enabled, the
device enters attack detection state. When the device detects that the sending rate of SYN packets
destined for the specified IP address constantly reaches or exceeds the specified action threshold,
the device considers the IP address to be under attack, enters attack protection state, and takes
protection actions as configured.
low
rate-number
: Sets the silence threshold for SYN flood attack protection of the specified IP
address. The
rate-number
argument indicates the number of SYN packets sent to the specified IP
address per second and is in the range of 1 to 64000. The default value of the silence threshold is 3/4
of the action threshold. When the device is in attack protection state, if it detects that the sending rate