- 307 -
packets ingress having TCP FIN, URG, and PSH all set and TCP Sequence Number set to 0, the
packets will be dropped if the mode is enabled.
Syntax
dos-control tcpfinurgpsh
no dos-control tcpfinurgpsh
no -
This command disables the TCP FIN and URG and PSH and SEQ=0 checking Denial of
Service protections.
Default Setting
Disabled
Command Mode
Global Config
7.13.2.14 dos-control tcpsyn
This command enables the TCP SYN and L4 source = 0-1023 Denial of Service protection. If the mode
is enabled, Denial of Service prevention is active for this type of attack. If packets ingress having TCP
flag SYN set and an L4 source port from 0 to 1023, the packets will be dropped if the mode is enabled.
Syntax
dos-control tcpsyn
no dos-control tcpsyn
no -
This command disables the TCP SYN and L4 source = 0-1023 Denial of Service protection.
Default Setting
Disabled
Command Mode
Global Config
7.13.2.15 dos-control tcpsynfin
This command enables the TCP SYN and FIN Denial of Service protection. If the mode is enabled,
Denial of Service prevention is active for this type of attack. If packets ingress having TCP flags SYN
and FIN set, the packets will be dropped if the mode is enabled.
Summary of Contents for 548B
Page 1: ...FortiSwitch 548B Version 5 2 0 2 Administration Guide...
Page 492: ...492 Default Setting Decrement 10 Command Mode Interface Config...
Page 869: ...869...
Page 976: ...www fortinet com...