SYN Protection Commands
show security-suite syn protection
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x
453
34
Interface Operational Last Attack
Name Status
----------- ------------- ---------------------------------------------
gi13 Normal 00:57:11 01-Jan-2000 blocked and reported
The following table describes the significant fields shown in the example:
Field
Description
Protection Mode
Action when the SYN flood attack is detected.
•
Block—The TCP SYN traffic from attacking
ports destined to the local system is blocked,
and a rate-limited syslog message is generated.
•
Disabled—The SYN protection feature is
disabled.
•
Report—The TCP SYN traffic from attacking
ports destined to the local system is blocked,
and a rate-limited syslog message is generated.
The SYN protection feature reports about TCP
SYN traffic per port (including rate-limited
syslog message when an attack is identified).
Threshold
Number of packets per second from a specific port
that triggers identification of TCP SYN attack.
Recovery
Auto-recovery timeout by which a port from which
SYN packets are blocked gets unblocked.
Interface Name
Interface identifier.
Operational Status
Shows that SYN protection is enabled or disabled on
the interface.
Last Attack
Time of the last SYN flood attack detected on the
interface.