Reducing the stale timeout can be an effective way to counter the effects of SYN flood Denial of
Service attacks on server resources. A stale timeout of 10.0 (see table below) would be an
appropriate value for a site under SYN flood attack.
Parameter
Minimum
Default
Maximum
Units
idle timeout
1.0
60.0
65535.0
seconds
stale timeout
1.0
30.0
120.0
seconds
Note that if you change the stale timeout setting while partially established Layer 4 connections
are currently in the queue, those connections will be affected by the new setting.
Application Server Timeouts
Keep in mind that the application server running on the physical servers in your cluster may have
its own timeout parameters that will affect the length of time the server keeps connections to
Equalizer and the client open. For example, an Apache 2 server has two related timeout
directives:
TimeOut and KeepAliveTimeout
:
1. The
TimeOut
directive currently defines the amount of time Apache will wait for three things:
a. The total amount of time it takes to receive a GET request.
b. The amount of time between receipt of TCP packets on a POST or PUT request.
c. The amount of time between ACKs on transmissions of TCP packets in
responses.
2. The
KeepAliveTimeout
directive specifies the number of seconds Apache will wait for a sub-
sequent request before closing the connection. Once a request has been received, the
timeout value specified by the Timeout directive applies.
In general, if you want Equalizer to control connection timeouts, you must make sure that any
timeouts set on the application server are of longer duration than the values set on Equalizer.
For example, with respect to the Apache server timeouts above, the client timeout (for Layer 7
connections) or the idle timeout (for Layer 4 connections) should be of shorter duration than the
timeouts set for Apache.
Similarly, the Layer 7 server timeout and connect timeout on Equalizer should be of shorter
duration than the TCP connection timeouts set on the servers.
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
All Rights Reserved.
325
Equalizer Administration Guide
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......