EasyManuals Logo

Cisco SG500-28P Administration Guide

Cisco SG500-28P
548 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #427 background imageLoading...
Page #427 background image
Security
Denial of Service Prevention
409 Cisco 500 Series Stackable Managed Switch Administration Guide Release 1.3
20
SYN Protection
The network ports might be used by hackers to attack the device in a SYN attack,
which consumes TCP resources (buffers) and CPU power.
Since the CPU is protected using SCT, TCP traffic to the CPU is limited. However, if
one or more ports are attacked with a high rate of SYN packets, the CPU receives
only the attacker packets, thus creating Denial-of-Service.
When using the SYN protection feature, the CPU counts the SYN packets
ingressing from each network port to the CPU per second.
If the number is higher than the specific, user-defined threshold, a deny SYN with
MAC-to-me rule is applied on the port. This rule is unbound from the port every
user-defined interval (SYN Protection Period).
To configure SYN protection:
STEP 1 Click Security > Denial of Service Prevention > SYN Protection.
STEP 2 Enter the parameters.
Block SYN-FIN Packets—Select to enable the feature. All TCP packets with
both SYN and FIN flags are dropped on all ports.
SYN Protection Mode—Select between three modes:
- DisableThe feature is disabled on a specific interface.
- Report—Generates a SYSLOG message.The status of the port is
changed to Attacked when the threshold is passed.
- Block and ReportWhen a TCP SYN attack is identified, TCP SYN
packets destined for the system are dropped and the status of the port is
changed to Blocked.
SYN Protection Threshold—Number of SYN packets per second before
SYN packets will be blocked (deny SYN with MAC-to-me rule will be applied
on the port).
SYN Protection PeriodTime in seconds before unblocking the SYN
packets (the deny SYN with MAC-to-me rule is unbound from the port).
STEP 3 Click Apply. SYN protection is defined, and the Running Configuration file is
updated.
The SYN Protection Interface Table displays the following fields for every port or
LAG (as requested by the user)

Table of Contents

Other manuals for Cisco SG500-28P

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco SG500-28P and is the answer not in the manual?

Cisco SG500-28P Specifications

General IconGeneral
Switching Capacity56 Gbps
Forwarding Rate41.67 Mpps
Flash Memory32 MB
Operating Humidity10% to 90% non-condensing
PoEYes
LayerLayer 2 and Layer 3
StackableYes
Power SupplyInternal
ManagementWeb-based GUI, CLI, SNMP
Jumbo Frame SupportYes
VLANs4096 VLANs
MAC Address Table Size16K entries
Dimensions440 x 44 x 350 mm
Operating Temperature0°C to 45°C
Ports28 (24 x 10/100/1000 PoE+ ports, 4 x 10/100/1000/SFP combo ports)

Related product manuals