![Radware Alteon Скачать руководство пользователя страница 392](http://html.mh-extra.com/html/radware/alteon/alteon_application-manual_781134392.webp)
Alteon Application Switch Operating System Application Guide
Filtering and Traffic Manipulation
392
Document
ID:
RDWR-ALOS-V2900_AG1302
Any filter may be set to match against more than one TCP flag at the same time. If there is more
than one flag enabled, the flags are applied with a logical AND operator. For example, by setting
Alteon to filter SYN and ACK, Alteon filters all SYN-ACK frames.
Notes
•
TCP flag filters must be cache-disabled. Exercise caution when applying cache-enabled and
cache-disabled filters to the same port. For more information, see
.
•
With IPv6, TCP health checks end with an RST flag instead of FIN as in IPv4.
Configuring the TCP Flag Filter
By default, all TCP filter options are disabled. TCP flags are not inspected unless one or more TCP
options are enabled.
Consider the network as illustrated in
Figure 63 - TCP Flag Filter Configuration Example, page 392
.:
Figure 63: TCP Flag Filter Configuration Example
In this network, the Web servers inside the LAN must be able to transfer mail to any SMTP-based
mail server out on the Internet. At the same time, you want to prevent access to the LAN from the
Internet, except for HTTP.
SMTP traffic uses well-known TCP port 25. The Web servers originates TCP sessions to the SMTP
server using TCP destination port 25, and the SMTP server acknowledges each TCP session and data
transfer using TCP source port 25.
Creating a filter with the ACK flag closes one potential security hole. Without the filter, Alteon
permits a TCP SYN connection request to reach any listening TCP destination port on the Web
servers inside the LAN, as long as it originated from TCP source port 25. The server would listen to
the TCP SYN, allocate buffer space for the connection, and reply to the connect request. In some
SYN attack scenarios, this could cause the server's buffer space to fill, crashing the server or at least
making it unavailable.
A filter with the ACK flag enabled prevents external devices from beginning a TCP connection (with a
TCP SYN) from TCP source port 25. Alteon drops any frames that have the ACK flag turned off.
Содержание Alteon
Страница 2: ...Alteon Application Switch Operating System Application Guide 2 Document ID RDWR ALOS V2900_AG1302 ...
Страница 42: ...Alteon Application Switch Operating System Application Guide Preface 42 Document ID RDWR ALOS V2900_AG1302 ...
Страница 582: ...Alteon Application Switch Operating System Application Guide High Availability 582 Document ID RDWR ALOS V2900_AG1302 ...