ip tcp syn-rst

Drops TCP control packets with both SYN and RST flags set.
Syntax
ip tcp syn-rst
no ip tcp syn-rst
Command Default

By default, the packets are not dropped.

Modes

Global configuration mode

Usage Guidelines

This command is supported for ICX 8100 and ICX 8200 devices only.

The no form of the command returns the ICX device to the default setting.

Examples

The following example configures the ICX device to drop TCP packets with both SYN and RST flags set, which could signal a DDOS attack.

device# configure terminal
device(config)# ip tcp syn-rst
History
Release version Command history
10.0.00 This command was introduced.