ip tcp syn-fin

Drops TCP control packets received with both SYN and FIN flags set.
Syntax
ip tcp syn-fin
no ip tcp syn-fin
Command Default

By default, the packets are not dropped.

Modes

Global configuration mode

Usage Guidelines

This command is supported for ICX 8100 and ICX 8200 devices only.

The no form of the command resets the ICX device to the default.

Examples

The following example configures the ICX device to drop TCP packets received with both SYN and FIN flags set, which could signal a DDOS attack.

device# configure terminal
device(config)# no ip tcp syn-fin
History
Release version Command history
10.0.00 This command was introduced.