1458 Denial of Service Commandsdos-control tcpflagUse the dos-control tcpflag command in Global Configuration mode toenable TCP Flag Denial of Service protections. If the mode is enabled, Denialof Service prevention is active for this type of attack. If packets ingress havingTCP Flag SYN set and a source port less than 1024, having TCP ControlFlags set to 0 and TCP Sequence Number set to 0, having TCP Flags FIN,URG, and PSH set and TCP Sequence Number set to 0, or having TCP FlagsSYN and FIN both set, the packets are dropped.Syntaxdos-control tcpflagno dos-control tcpflagDefault ConfigurationDenial of Service is disabled.Command ModeGlobal Configuration mode.User GuidelinesThis command has no user guidelines.ExampleThe following example activates TCP Flag Denial of Service protections.console(config)#dos-control tcpflagdos-control tcpfragUse the dos-control tcpfrag command in Global Configuration mode toenable TCP Fragment Denial of Service protection. If the mode is enabled,Denial of Service prevention is active for this type of attack. If packets ingresshaving IP Fragment Offset equal to one (1), the packets are dropped.Syntaxdos-control tcpfrag