Configuring Security
Denial of Service Prevention
Cisco 500 Series Stackable Managed Switch Administration Guide
334
18
•
IP Address
—Enter an IP addresses to reject. The possible values are:
-
From reserved List
—Select a well-known IP address from the reserved
list.
-
New IP Address
—Enter an IP address.
•
Mask
—Enter the mask of the IP address to define a range of IP addresses to
reject. The values are:
-
Network Mask
—Network mask in dotted decimal format.
-
Prefix Length
—Enter the prefix of the IP address to define the range of IP
addresses for which Denial of Service prevention is enabled.
STEP 5
Click
Apply
. The Martian addresses are written to the Running Configuration file.
Define SYN Filtering
The
SYN Filtering
page
enables
filtering TCP packets that contain a SYN flag, and
are destined for one or more ports.
To define a SYN filter:
STEP 1
Click
Security
>
Denial of Service Prevention
>
SYN Filtering
. The
SYN Filtering
page is displayed. SYN Filtering Page
STEP 2
Click
Add
. The
Add SYN Filtering
page is displayed.
STEP 3
Enter the parameters.
•
Interface
—Select the interface on which the filter is defined.
•
IPv4 Address
—Enter the IP address for which the filter is defined, or select
All Addresses
.
•
Network Mask
—Enter the network mask for which the filter is enabled in IP
address format.
•
TCP Port
—Select the destination TCP port being filtered:
-
Known Ports
—Select a port from the list.
-
User Defined
—Enter a port number.
-
All Ports
—Select to indicate that all ports are filtered.