Chapter 24: General Security Measures
Port-based Traffic Segmentation
– 889 –
C
OMMAND
M
ODE
Global Configuration
E
XAMPLE
Console(config)#dos-protection win-nuke 65
Console(config)#
show
dos-protection
This command shows the configuration settings for the DoS protection
commands.
C
OMMAND
M
ODE
Privileged Exec
E
XAMPLE
Console#show dos-protection
Global DoS Protection:
Echo/Chargen Attack : Disabled, 1000 kilobits per second
Smurf Attack : Enabled
TCP Flooding Attack : Disabled, 1000 kilobits per second
TCP Null Scan : Enabled
TCP SYN/FIN Scan : Enabled
TCP/UDP Packets with Port 0 : Enabled
TCP XMAS Scan : Enabled
UDP Flooding Attack : Disabled, 1000 kilobits per second
WinNuke Attack : Disabled, 1000 kilobits per second
Console#
P
ORT
-
BASED
T
RAFFIC
S
EGMENTATION
If tighter security is required for passing traffic from different clients through downlink ports on the local network and over uplink ports to the service provider, port-based traffic segmentation can be used to isolate traffic for individual clients.
Traffic belonging to each client is isolated to the allocated downlink ports.
But the switch can be configured to either isolate traffic passing across a
client’s allocated uplink ports from the uplink ports assigned to other
clients, or to forward traffic through the uplink ports used by other clients,
allowing different clients to share access to their uplink ports where
security is less likely to be compromised.
Table 24-14: Commands for Configuring Traffic Segmentation
Command
Function
Mode
Enables traffic segmentation
GC
Creates a client session
GC
Configures uplink/downlink ports for client sessions GC
Summary of Contents for SSE-G2252
Page 42: ...44 General IP Routing on page 627...
Page 603: ...Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 609...
Page 883: ...Chapter 24 General Security Measures Port based Traffic Segmentation 894...
Page 989: ...Chapter 30 Congestion Control Commands Automatic Traffic Control Commands 1000 Console...
Page 1007: ...Chapter 33 Address Table Commands 1019...
Page 1137: ...Chapter 38 Quality of Service Commands 1150...