ip tcp tcp-all

Drops TCP control packets with irregularities that typically signal DDOS attacks.
Syntax
ip tcp tcp-all
no ip tcp tcp-all
Command Default

By default, the packets are not dropped.

Modes

Global configuration mode

Usage Guidelines

This command is supported for ICX 8100 and ICX 8200 devices only.

When the ip tcp tcp-all command is configured, the ICX device drops TCP control packets received with any of the following irregularities:

  • sent using the MAC Multicast mechanism
  • all flags set to zero
  • FIN URG and PSH flags set
  • both SYN and FIN flags in TCP packet set
  • both SYN and RST flags in TCP packet set
  • source or destination port set to zero

The no form of the command returns the ICX device to the default setting.

Examples

The following example configures the ICX device to drop TCP packets with specific irregularities that typically signal a DDOS attack.

device# configure terminal
device(config)# no ip tcp tcp-all
History
Release version Command history
10.0.00 This command was introduced.