5-27
Cisco Content Services Switch Administration Guide
OL-5647-02
Chapter 5 Configuring Simple Network Management Protocol (SNMP)
Configuring Denial of Service (DoS)
Table 5-3 Field Descriptions for the show dos Command
Field Description
Total Attacks The total number of DoS attacks detected since the
CSS was booted. The type of attacks that are listed
along with their number of occurrences are:
• SYN Attacks - TCP connections that are initiated
by a source but are not followed with an ACK
frame to complete the three way TCP handshake
• LAND Attacks - Packets that have identical
source and destination addresses
• Zero Port Attacks - Frames that contain source
or destination TCP or UDP ports equal to zero
Note Older SmartBits software may send frames
containing source or destination ports equal to
zero. The CSS logs them as DoS attacks and
drops these frames.
• Illegal Src Attacks - Illegal source addresses
• Illegal Dst Attacks - Illegal destination addresses
• Smurf Attacks - Pings with a broadcast
destination address
First Attack Detected The first time a DoS attack was detected.
Last Attack Detected The last time a DoS attack was detected.