[c-nsp] syn flood - port 80

Roger grunky at rockriver.net
Sun Aug 1 20:21:35 EDT 2004


I'm wondering how one would slow down a syn flood attack on hosts @ port 80?

I'm running a 7206vxr at the border and would like to slow a syn flood 
attack w/o clobbering my customers web servers...

Traffic policing would be bad as to high of a percentage of syn packets 
are junk, traffic shaping would help BUT all my customers web servers 
would respond slower....

Any urls or guides would be helpful.


Thanks.


More information about the cisco-nsp mailing list