EasyManuals Logo

Edge-Core ECS4620-28F User Manual

Edge-Core ECS4620-28F
2143 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #1207 background imageLoading...
Page #1207 background image
Chapter 9
| General Security Measures
Denial of Service Protection
– 377 –
Example
Console(config)#dos-protection tcp-null-scan
Console(config)#
dos-protection
tcp-syn-fin-scan
This command protects against DoS TCP-SYN/FIN-scan attacks in which a TCP SYN/
FIN scan message is used to identify listening TCP ports. The scan uses a series of
strangely configured TCP packets which contain SYN (synchronize) and FIN (finish)
flags. If the target's TCP port is closed, the target replies with a TCP RST (reset)
packet. If the target TCP port is open, it simply discards the TCP SYN FIN scan. Use
the no form to disable this feature.
Syntax
[no] dos-protection syn-fin-scan
Default Setting
Enabled
Command Mode
Global Configuration
Example
Console(config)#dos-protection syn-fin-scan
Console(config)#
dos-protection
tcp-udp-port-zero
This command protects against DoS attacks in which the TCP or UDP source port or
destination port is set to zero. This technique may be used as a form of DoS attack,
or it may just indicate a problem with the source device. When this command is
enabled, the switch will drop these packets. Use the no form to restore the default
setting.
Syntax
[no] dos-protection tcp-udp-port-zero
Default Setting
Enabled
Command Mode
Global Configuration
Example
Console(config)#dos-protection tcp-udp-port-zero
Console(config)#

Table of Contents

Other manuals for Edge-Core ECS4620-28F

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Edge-Core ECS4620-28F and is the answer not in the manual?

Edge-Core ECS4620-28F Specifications

General IconGeneral
BrandEdge-Core
ModelECS4620-28F
CategorySwitch
LanguageEnglish

Related product manuals