![Cisco Sx350 Скачать руководство пользователя страница 277](http://html.mh-extra.com/html/cisco/sx350/sx350_cli-manual_2609320277.webp)
Denial of Service (DoS) Commands
Cisco Sx350 Ph. 2.2.5 Devices - Command Line Interface Reference Guide
276
10
User Guidelines
On ports in which an ACL is defined (user-defined ACL etc.), this feature cannot block TCP SYN
packets. In case the protection mode is block but SYN Traffic cannot be blocked, a relevant
SYSLOG message will be created, e.g.: “port gi11 is under TCP SYN attack. TCP SYN traffic
cannot be blocked on this port since the port is bound to an ACL.”
Examples
Example 1:
The following example sets the TCP SYN protection feature to report
TCP SYN attack on ports in case an attack is identified from these ports.
switchxxxxxx(config)#
security-suite syn protection mode report
…
01-Jan-2012 05:29:46:
A TCP SYN Attack was identified on port
gi1
1
Example 2:
The following example sets the TCP SYN protection feature to block
TCP SYN attack on ports in case an attack is identified from these ports.
switchxxxxxx(config)#
security-suite syn protection mode block
…
01-Jan-2012 05:29:46:
A TCP SYN Attack was identified on port
gi1
1. TCP SYN
traffic destined to the local system is automatically blocked for 100
seconds.
10.10 security-suite syn protection recovery
To set the time period for the SYN Protection feature to block an attacked
interface, use the security-suite syn protection period Global Configuration mode
command.
To set the time period to its default value, use the no form of this command.
Syntax
security-suite syn protection recovery timeout
no security-suite syn protection recovery
Содержание Sx350
Страница 1: ...Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide CLI GUIDE ...
Страница 26: ...25 Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 1 ...
Страница 237: ...CDP Commands Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 236 8 ...
Страница 503: ...IGMP Snooping Commands Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 502 23 1000 239 255 0 7 ...
Страница 532: ...IP Routing Protocol Independent Commands 531 Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 25 ...
Страница 736: ...IPv6 Prefix List Commands 735 Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 31 ...
Страница 975: ...RADIUS Commands Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 974 48 ...
Страница 1297: ...Virtual Local Area Network VLAN Commands Cisco Sx350 Ph 2 2 5 Devices Command Line Interface Reference Guide 1296 67 4086 802 1x ...