Cisco 4700M Configuration Manual page 321

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Chapter 4
Configuring TCP/IP Normalization and IP Reassembly Parameters
Displaying Configurations and Statistics for TCP/IP and UDP Connections, IP Reassembly, and SYN Cookie
.
OL-16202-01
For example, to display SYN cookie statistics for VLAN 100, enter:
host1/C1# show syn-cookie vlan 100
Table 4-15
describes the fields in the show syn-cookie command output.
Table 4-15
Field Descriptions for the show syn-cookie Command Output
Field
Description
Interface
Name of the VLAN interface configured on the ACE.
Configured TCP
Configured embryonic connection threshold above which
Embryonic
the ACE applies SYN-cookie DoS protection.
Connection Limit
Current TCP
Number of embryonic connections that the ACE is currently
Embryonic
tracking.
Connection Limit
Number of TCP
Number of client SYN packets that the ACE intercepted
SYNs Intercepted
because the SYN-cookie embryonic connection threshold
by SYN COOKIE
was exceeded.
Number of TCP
Number of client ACK packets that the ACE saw and that
ACKs
matched a given SYN cookie. Each client ACK that matches
Successfully
a cookie creates a valid embryonic connection on the ACE.
Processed by
SYN COOKIE
Failed Number of
Number of client ACK packets that did not match a SYN
TCP ACKs
cookie.
Processed by
SYN COOKIE
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
4-63

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents