Configuring TCP SYN Threshold Values on an Interface

TCP SYN threshold values can be configured globally, at the physical interface level, or at the VLAN level. Perform the following steps to set threshold values at the interface level.

  1. Enter global configuration mode.
    device# configure terminal
  2. Specify the interface to be configured.
    device(config)# interface ethernet 1/3/11
  3. In interface configuration mode, specify the threshold values for TCP SYN traffic received in packets per second. On the same line, specify the lockup time in seconds.
    device(config-if-e1000-1/3/11)# ip tcp burst-normal 30 burst-max 100 lockup 300

The following example configures the TCP/SYN attack protection at the VLAN level. For Layer 3 router code, if the interface is part of a VLAN that has a router VE, you must configure TCP/SYN attack protection at the VLAN level. When TCP/SYN attack protection is configured at the VLAN level, it applies to routed traffic only. It does not affect switched traffic.

Note: You must configure VLAN information for the port before configuring TCP/SYN attack protection. You cannot change the VLAN configuration for a port on which TCP/SYN attack protection is enabled.
device# configure terminal
device(config)# vlan 2
device(config-vlan-2)# ip tcp burst-normal 5000 burst-max 10000 lockup 300