![Cisco Sx350 Скачать руководство пользователя страница 270](http://html.mh-extra.com/html/cisco/sx350/sx350_cli-manual_2609320270.webp)
Denial of Service (DoS) Commands
269
Cisco Sx350 Ph. 2.2.5 Devices - Command Line Interface Reference Guide
10
Syntax
security-suite deny syn {
[add {tcp-port | any} {ip-address | any} {mask |
/prefix-length}] |
[remove {tcp-port | any} {ip-address | any} {mask | /prefix-length}]}
no security-suite deny syn
Parameters
•
ip-address | any—Specifies the destination IP address. Use any to specify
all IP addresses.
•
mask— Specifies the network mask of the destination IP address.
•
prefix-length—Specifies the number of bits that comprise the destination IP
address prefix. The prefix length must be preceded by a forward slash (/).
•
tcp-port | any—Specifies the destination TCP port. The possible values are:
http, ftp-control, ftp-data, ssh, telnet, smtp, or port number. Use any to
specify all ports.
Default Configuration
Creation of TCP connections is allowed from all interfaces.
If the mask is not specified, it defaults to 255.255.255.255.
If the
prefix-length
is not specified, it defaults to 32.
Command Mode
Interface (Ethernet, Port Channel) Configuration mode
User Guidelines
For this command to work,
show security-suite configuration
must be enabled
both globally and for interfaces.
The blocking of TCP connection creation from an interface is done by discarding
ingress TCP packets with "SYN=1", "ACK=0" and "FIN=0" for the specified
destination IP addresses and destination TCP ports.
Example
The following example attempts to block the creation of TCP connections from an
interface. It fails because security suite is enabled globally and not per interface.
Содержание Sx350
Страница 1: ...Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide CLI GUIDE ...
Страница 26: ...25 Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 1 ...
Страница 237: ...CDP Commands Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 236 8 ...
Страница 503: ...IGMP Snooping Commands Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 502 23 1000 239 255 0 7 ...
Страница 532: ...IP Routing Protocol Independent Commands 531 Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 25 ...
Страница 736: ...IPv6 Prefix List Commands 735 Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 31 ...
Страница 975: ...RADIUS Commands Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 974 48 ...
Страница 1297: ...Virtual Local Area Network VLAN Commands Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 1296 67 4086 802 1x ...