authentication dos-protection
authentication dos-protection
{
enable
|
mac-limit
mac-limit-value
}
no authentication dos-protection
{
enable
|
mac-limit
mac-limit-value
}
Denial of service is disabled by default.
Interface configuration mode
The
no form of the command disables DoS protection.
To limit the susceptibility of the ICX device to DoS attacks, you can configure the device to use multiple RADIUS servers, which can share the load when there are a large number of MAC addresses that need to be authenticated. The ICX device can run a maximum of 10 RADIUS clients per server and will attempt to authenticate with a new RADIUS server if current one times out.
In addition, you can configure the ICX device to limit the rate of authentication attempts sent to the RADIUS server. When MAC authentication is enabled, the number of RADIUS authentication attempts made per second is tracked. When you also enable the DoS protection feature, if the number of RADIUS authentication attempts for MAC addresses learned on an interface per second exceeds a configurable rate (by default 512 authentication attempts per second), the device considers this a possible DoS attack and disables the port. You must then manually re-enable the port.
| Release version | Command history |
|---|---|
| 08.0.20 | This command was introduced. |