![Radware Alteon Скачать руководство пользователя страница 206](http://html.mh-extra.com/html/radware/alteon/alteon_application-manual_781134206.webp)
Alteon Application Switch Operating System Application Guide
Server Load Balancing
206
Document
ID:
RDWR-ALOS-V2900_AG1302
Configuring Delayed Binding
To configure delayed binding
Note:
Enable delayed binding without configuring any HTTP SLB processing or persistent binding
types.
To configure delayed binding for cache redirection, see
Delayed Binding for Cache Redirection,
.
Detecting SYN Attacks
In Alteon, SYN attack detection is enabled by default whenever delayed binding is enabled. SYN
attack detection includes the following capabilities:
•
Provides a way to track half open connections
•
Activates a trap notifying that the configured threshold has been exceeded
•
Monitors DoS attacks and proactively signals alarm
•
Provides enhanced security
•
Improves visibility and protection for DoS attacks
The probability of a SYN attack is higher if excessive half-open sessions are generated on Alteon.
Half-open sessions show an incomplete three-way handshake between the server and the client. You
can view the total number of half-open sessions from the
/stat/slb/layer7/maint
menu.
To detect SYN attacks, Alteon keeps track of the number of new half-open sessions for a set period.
If the value exceeds the threshold, then a syslog message and an SNMP trap are generated.
You can change the default parameters for detecting SYN attacks in the
/cfg/slb/adv/synatk
menu. You can specify how frequently you want to check for SYN attacks, from two seconds to one
minute, and modify the default threshold representing the number of new half-open sessions per
second.
Force Proxy Using the Application Service Engine
Alteon provides various application layer services which require a full TCP proxy behavior. Some of
these capabilities include SSL offloading, HTTP caching and compression, HTTP modifications, TCP
optimizations, and more. To facilitate these functionalities, Alteon includes a module named
Application Service Engine.
The Application Service Engine is a full TCP proxy which performs delayed binding of connections,
during which it can optimize TCP behavior, intercept client requests and server responses to modify
them, and so on. In some cases, the proxy behavior itself may be required even without the use of
any other application service. For this purpose, you can set delayed binding to Force Proxy mode. In
>> # /cfg/slb/virt <virtual server number> /service <service type> /dbind
Current delayed binding: disabled
Enter new delayed binding [d/e/f]:e
Содержание Alteon
Страница 2: ...Alteon Application Switch Operating System Application Guide 2 Document ID RDWR ALOS V2900_AG1302 ...
Страница 42: ...Alteon Application Switch Operating System Application Guide Preface 42 Document ID RDWR ALOS V2900_AG1302 ...
Страница 582: ...Alteon Application Switch Operating System Application Guide High Availability 582 Document ID RDWR ALOS V2900_AG1302 ...