Denial of Service (DoS) Commands
OL-32830-01 Command Line Interface Reference Guide
378
16
16.13 show security-suite syn protection
To display the SYN Protection feature configuration and the operational status per interface-id, including
the time of the last attack per interface, use the
show security-suite syn protection
switchxxxxxx>
command.
Syntax
show security-suite syn protection [interface-id]
Parameters
interface-id
—(Optional) Specifies an interface-ID. The interface-ID can be one of the following types:
Ethernet port of Port-Channel.
Command Mode
User EXEC mode
User Guidelines
Use the Interface-ID to display information on a specific interface.
Example
The following example displays the TCP SYN protection feature configuration and current status on all
interfaces. In this example, port gi12 is attacked but since there is a user-ACL on this port, it cannot
become blocked so its status is
Reported
and not
Blocked and Reported
.
switchxxxxxx#
show security-suite syn protection
Protection Mode: Block
Threshold: 40 Packets Per Second
Period: 100 Seconds
Interface Current Last
Name Status Attack
---------------- ------------------ --------------------------------------------------------------------------
Interface
---------------
gi1
2
IP Address
--------------
176.16.23.0\24
Fragmented packets filtering
Interface
--------------
gi1
2
IP Address
--------------
176.16.23.0\24
Содержание 300 Series
Страница 2: ......