EasyManuals Logo

Cisco 300 Series User Manual

Cisco 300 Series
1117 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #368 background imageLoading...
Page #368 background image
Denial of Service (DoS) Commands
OL-32830-01 Command Line Interface Reference Guide 368
16
Syntax
security-suite deny syn {
[add {tcp-port | any} {ip-address | any} {mask |
/prefix-length}] |
[remove {tcp-port | any} {ip-address | any} {mask | /prefix-length}]}
no security-suite deny syn
Parameters
• ip-address | any—Specifies the destination IP address. Use any to specify
all IP addresses.
• mask— Specifies the network mask of the destination IP address.
• prefix-length—Specifies the number of bits that comprise the destination IP
address prefix. The prefix length must be preceded by a forward slash (/).
• tcp-port | any—Specifies the destination TCP port. The possible values are:
http, ftp-control, ftp-data, ssh, telnet, smtp, or port number. Use any to
specify all ports.
Default Configuration
Creation of TCP connections is allowed from all interfaces.
If the mask is not specified, it defaults to 255.255.255.255.
If the
prefix-length
is not specified, it defaults to 32.
Command Mode
Interface (Ethernet, Port Channel) Configuration mode
User Guidelines
For this command to work, show security-suite configuration must be enabled
both globally and for interfaces.
The blocking of TCP connection creation from an interface is done by discarding
ingress TCP packets with "SYN=1", "ACK=0" and "FIN=0" for the specified
destination IP addresses and destination TCP ports.
Example
The following example attempts to block the creation of TCP connections from an
interface. It fails because security suite is enabled globally and not per interface.

Table of Contents

Other manuals for Cisco 300 Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 300 Series and is the answer not in the manual?

Cisco 300 Series Specifications

General IconGeneral
ModelCisco 300 Series
CategorySwitch
DimensionsVaries by model
WeightVaries by model
Power over Ethernet (PoE)Available on select models
ManagementWeb-based GUI, SNMP, CLI
VLANsUp to 256
Security FeaturesACLs, 802.1X, Port Security
Humidity10% to 90% non-condensing
Ports8, 16, 24, 48

Related product manuals