Chapter 9
| General Security Measures
Denial of Service Protection
– 309 –
dos-protection
tcp-syn-fin-scan
This command protects against DoS TCP-SYN/FIN-scan attacks in which a
TCP SYN/FIN scan message is used to identify listening TCP ports. The scan
uses a series of strangely configured TCP packets which contain SYN
(synchronize) and FIN (finish) flags. If the target's TCP port is closed, the
target replies with a TCP RST (reset) packet. If the target TCP port is open, it
simply discards the TCP SYN FIN scan. Use the
no
form to disable this
feature.
Syntax
[
no
]
dos-protection tcp-syn-fin-scan
Default Setting
Disabled
Command Mode
Global Configuration
Example
Console(config)#dos-protection syn-fin-scan
Console(config)#
dos-protection
tcp-xmas-scan
This command protects against DoS TCP-xmas-scan in which a so-called
TCP XMAS scan message is used to identify listening TCP ports. This scan
uses a series of strangely configured TCP packets which contain a sequence
number of 0 and the URG, PSH and FIN flags. If the target's TCP port is
closed, the target replies with a TCP RST packet. If the target TCP port is
open, it simply discards the TCP XMAS scan. Use the
no
form to disable this
feature.
Syntax
[
no
]
dos-protection tcp-xmas-scan
Default Setting
Disabled
Command Mode
Global Configuration
Example
Console(config)#dos-protection tcp-xmas-scan
Console(config)#