Chapter 9
| General Security Measures
Denial of Service Protection
– 308 –
dos-protection
tcp-flooding
This command protects against DoS TCP-flooding attacks in which a
perpetrator sends a succession of TCP SYN requests (with or without a
spoofed-Source IP) to a target and never returns ACK packets. These
half-open connections will bind resources on the target, and no new
connections can be made, resulting in a denial of service. Use the
no
form
without the bit rate parameter to disable this feature, or with the bit rate
parameter to restore the default rate limit.
Syntax
[
no
]
dos-protection tcp-flooding
[
bit-rate-in-kilo
rate
]
rate
– Maximum allowed rate. (Range: 64-2000 kbits/second)
Default Setting
Disabled, 1000 kbits/second
Command Mode
Global Configuration
Example
Console(config)#dos-protection tcp-flooding bit-rate-in-kilo 65
Console(config)#
dos-protection
tcp-null-scan
This command protects against DoS TCP-null-scan attacks in which a TCP
NULL scan message is used to identify listening TCP ports. The scan uses a
series of strangely configured TCP packets which contain a sequence number
of 0 and no flags. If the target's TCP port is closed, the target replies with a
TCP RST (reset) packet. If the target TCP port is open, it simply discards the
TCP NULL scan. Use the
no
form to disable this feature.
Syntax
[
no
]
dos-protection tcp-null-scan
Default Setting
Disabled
Command Mode
Global Configuration
Example
Console(config)#dos-protection tcp-null-scan
Console(config)#
Содержание SC30010
Страница 1: ...C 300 Series Gigabit Managed Switch CLI Reference Guide SOFTWARE RELEASE V1 1 10 171 www signamax com ...
Страница 2: ...CLI Reference Guide SC30010 C 300 48 Port Gigabit Managed Switch E122017 KS R01 ...
Страница 482: ...Chapter 19 Class of Service Commands Priority Commands Layer 3 and 4 482 ...
Страница 670: ......
Страница 671: ...E122017 KS R01 ...