Configuring the Duration to Establish a
TCP Connection
You can configure the duration for which the device must wait before it attempts to establish a TCP
connection. Using this capability, you can limit the wait times for TCP connection requests. Upon responding
to the initial SYN packet that requests a connection to the router for a specific service (such as SSH or BGP)
with a SYN ACK, the router waits for a period of time for the ACK packet to be sent from the requesting host
that will establish the TCP connection.
You can set this duration or interval for which the TCP connection waits to be established to a significantly
high value to prevent the device from moving into an out-of-service condition or becoming unresponsive
during a SYN flood attack that occurs on the device. You can set the wait time to be 10 seconds or lower. If
the device does not contain any BGP connections with the BGP neighbors across WAN links, you must set
this interval to a higher value, depending on the complexity of your network and the configuration attributes.
To configure the duration for which the device waits for the ACK packet to be sent from the requesting host
to establish the TCP connection, perform the following steps:
1
Define the wait duration in seconds for the TCP connection to be established.
CONFIGURATION mode
Dell(conf)#ip tcp reduced-syn-ack-wait <9-75>
You can use the
no ip tcp reduced-syn-ack-wait
command to restore the default behavior,
which causes the wait period to be set as 8 seconds.
2 View the interval that you configured for the device to wait before the TCP connection is attempted to
be established.
EXEC mode
Dell>show ip tcp reduced-syn-ack-wait
Enabling Directed Broadcast
By default, Dell Networking OS drops directed broadcast packets destined for an interface. This default setting
provides some protection against denial of service (DoS) attacks.
To enable Dell Networking OS to receive directed broadcasts, use the following command.
• Enable directed broadcast.
INTERFACE mode
ip directed-broadcast
To view the configuration, use the
show config
command in INTERFACE mode.
IPv4 Routing
503
Содержание S4048T
Страница 1: ...Dell Configuration Guide for the S4048T ON System 9 10 0 1 ...
Страница 98: ... saveenv 7 Reload the system uBoot mode reset Management 98 ...
Страница 113: ...Total CFM Pkts 10303 CCM Pkts 0 LBM Pkts 0 LTM Pkts 3 LBR Pkts 0 LTR Pkts 0 802 1ag 113 ...
Страница 411: ...mode transit no disable Force10 Resilient Ring Protocol FRRP 411 ...
Страница 590: ...Figure 67 Inspecting the LAG Configuration Link Aggregation Control Protocol LACP 590 ...
Страница 591: ...Figure 68 Inspecting Configuration of LAG 10 on ALPHA Link Aggregation Control Protocol LACP 591 ...
Страница 594: ...Figure 70 Inspecting a LAG Port on BRAVO Using the show interface Command Link Aggregation Control Protocol LACP 594 ...
Страница 595: ...Figure 71 Inspecting LAG 10 Using the show interfaces port channel Command Link Aggregation Control Protocol LACP 595 ...
Страница 646: ...Figure 87 Configuring Interfaces for MSDP Multicast Source Discovery Protocol MSDP 646 ...
Страница 647: ...Figure 88 Configuring OSPF and BGP for MSDP Multicast Source Discovery Protocol MSDP 647 ...
Страница 648: ...Figure 89 Configuring PIM in Multiple Routing Domains Multicast Source Discovery Protocol MSDP 648 ...
Страница 653: ...Figure 91 MSDP Default Peer Scenario 2 Multicast Source Discovery Protocol MSDP 653 ...
Страница 654: ...Figure 92 MSDP Default Peer Scenario 3 Multicast Source Discovery Protocol MSDP 654 ...
Страница 955: ...Figure 119 Single and Double Tag First byte TPID Match Service Provider Bridging 955 ...
Страница 1179: ...Figure 147 Create Hypervisor Figure 148 Edit Hypervisor Figure 149 Create Transport Connector Virtual Extensible LAN VXLAN 1179 ...