Chapter 5: Switching Commands 573
dos-control
tcpsynfin
This command enables TCP SYN and FIN Denial of Service protection. If the
mode is enabled, Denial of Service prevention is active for this type of attack. If
packets ingress having TCP flags SYN and FIN set, the packets will be dropped
if the mode is enabled.
no dos-control
tcpsynfin
This command sets disables TCP SYN & FIN Denial of Service protection.
dos-control
tcpfinurgpsh
This command enables TCP FIN and URG and PSH and SEQ = 0 checking
Denial of Service protections. If the mode is enabled, Denial of Service
prevention is active for this type of attack. If packets ingress having TCP FIN,
URG, and PSH all set and TCP Sequence Number set to 0, the packets will be
dropped if the mode is enabled.
no dos-control
tcpfinurgpsh
This command sets disables TCP FIN and URG and PSH and SEQ = 0 checking
Denial of Service protections.
Default disabled
Format
dos-control tcpsynfin
Mode Global Config
Format
no dos-control tcpsynfin
Mode Global Config
Default disabled
Format
dos-control tcpfinurgpsh
Mode Global Config
Format
no dos-control tcpfinurgpsh
Mode Global Config