Filter and Firewall
Left running head:
Chapter name (automatic)
628
Beta
Beta
OmniAccess 700 CLI Command Reference Guide
Alcatel-Lucent
TCP
-
SYN
-
FLOOD
tcp-syn-flood
[{
threshold
<
1-4294967295
> <
1-4294967295
>
|
timeout
<
1-4294967295
>}]
D
ESCRIPTION
The server builds in its system memory a data structure describing all pending
connections. This data structure is of finite size, and it can be made to overflow by
intentionally creating too many partially-open connections. Systems providing
TCP-based services to the Internet community may be unable to provide services
while under this attack and for some time after this attack ceases. To protect the
system from this attack, use this command.
P
ARAMETERS
D
EFAULT
V
ALUE
•
2 packets per 10 milliseconds
•
5000 microseconds is the Default
E
XAMPLE
Consider the following example, here if you do not explicitly provide the threshold
value for the attack, the default value is taken:
ALU(config-attack A4)# tcp-syn-flood
Parameter
Description
threshold
Threshold limit set.
1-4294967295
Number of packets permissible within a defined
interval.
1-4294967295
The limiting time to which the packets can be sent.
timeout
<
1-4294967295>
TCP Proxy timeout in seconds