![Cisco Sx350 Скачать руководство пользователя страница 274](http://html.mh-extra.com/html/cisco/sx350/sx350_cli-manual_2609320274.webp)
Denial of Service (DoS) Commands
273
Cisco Sx350 Ph. 2.2.5 Devices - Command Line Interface Reference Guide
10
This command rate limits ingress TCP packets with "SYN=1", "ACK=0" and "FIN=0"
for the specified destination IP addresses.
SYN attack rate limiting is implemented after the security suite rules are applied to
the packets. The ACL and QoS rules are not applied to those packets.
Since the hardware rate limiting counts bytes, it is assumed that the size of “SYN”
packets is short.
Example
The following example attempts to rate limit DoS SYN attacks on a port. It fails
because security suite is enabled globally and not per interface.
switchxxxxxx(config)#
security-suite enable global-rules-only
switchxxxxxx(config)#
interface
gi1
1
switchxxxxxx(config-if)#
security-suite dos syn-attack 199 any /10
To perform this command, DoS Prevention must be enabled in the per-interface mode.
10.8 security-suite enable
To enable the security suite feature, use the security-suite enable Global
Configuration mode command. This feature supports protection against various
types of attacks.
When this command is used, hardware resources are reserved. These hardware
resources are released when the no security-suite enable command is entered.
The security-suite feature can be enabled in one of the following ways:
•
Global-rules-only—This enables the feature globally but per-interface
features are not enabled.
•
All (no keyword)—The feature is enabled globally and per-interface.
To disable the security suite feature, use the no form of this command.
When security-suite is enabled, you can specify the types of protection required.
The following commands can be used:
•
show security-suite configuration
•
show security-suite configuration
•
Содержание Sx350
Страница 1: ...Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide CLI GUIDE ...
Страница 26: ...25 Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 1 ...
Страница 237: ...CDP Commands Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 236 8 ...
Страница 503: ...IGMP Snooping Commands Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 502 23 1000 239 255 0 7 ...
Страница 532: ...IP Routing Protocol Independent Commands 531 Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 25 ...
Страница 736: ...IPv6 Prefix List Commands 735 Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 31 ...
Страница 975: ...RADIUS Commands Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 974 48 ...
Страница 1297: ...Virtual Local Area Network VLAN Commands Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 1296 67 4086 802 1x ...