authentication dos-protection

Enables denial of service (DoS) authentication protection on the interface.
Syntax
authentication dos-protection { enable | mac-limit mac-limit-value }
no authentication dos-protection { enable | mac-limit mac-limit-value }
Command Default

Denial of service is disabled by default.

Parameters
enable
Specifies to enable DoS protection.
mac-limit
Specifies the maximum number MAC-authentication attempts allowed per second.
mac-limit-value
Specifies the rate limit for DoS protection. You can specify a rate from 1 - 65535 authentication attempts per second. The default is a rate of 512 authentication attempts per second.
Modes

Interface configuration mode

Usage Guidelines

The no form of the command disables DoS protection.

To limit the susceptibility of the ICX device to DoS attacks, you can configure the device to use multiple RADIUS servers, which can share the load when there are a large number of MAC addresses that need to be authenticated. The ICX device can run a maximum of 10 RADIUS clients per server and will attempt to authenticate with a new RADIUS server if current one times out.

In addition, you can configure the ICX device to limit the rate of authentication attempts sent to the RADIUS server. When MAC authentication is enabled, the number of RADIUS authentication attempts made per second is tracked. When you also enable the DoS protection feature, if the number of RADIUS authentication attempts for MAC addresses learned on an interface per second exceeds a configurable rate (by default 512 authentication attempts per second), the device considers this a possible DoS attack and disables the port. You must then manually re-enable the port.

Examples

The example specifies the DoS protection count as 256.

device(config)# authentication
device(config-authen)# interface ethernet 1/3/1
device(config-if-e1000-1/3/1)# authentication dos-protection mac-limit 256
History
Release version Command history
08.0.20 This command was introduced.