Download Print this page

HP FlexNetwork MSR Series Command Reference Manual page 690

Comware 7 security
Hide thumbs Also See for FlexNetwork MSR Series:

Advertisement

Default
TCP SYN check is disabled.
Views
ASPF policy view
Predefined user roles
network-admin
Usage guidelines
TCP SYN check checks the first packet to establish a TCP connection whether it is a SYN packet. If
the first packet is not a SYN packet, ASPF drops the packet.
When a router attached to the network is started up, it can receive a non-SYN packet of an existing
TCP connection for the first time. If you do not want to interrupt the existing TCP connection, you can
disable the TCP SYN check. Then, the router allows the non-SYN packet that is the first packet to
establish a TCP connection to pass. After the network topology becomes steady, you can enable
TCP SYN check again.
Examples
# Enable TCP SYN check for ASPF policy 1.
<Sysname> system-view
[Sysname] aspf policy 1
[Sysname-aspf-policy-1] tcp syn-check
Related commands
aspf policy
672

Advertisement

loading