Tcp Attack Protection Configuration; Tcp Attack Protection Overview; Enabling The Syn Cookie Feature; Displaying And Maintaining Tcp Attack Protection - HP 5120 EI Switch Series Configuration Manual

Hide thumbs Also See for 5120 EI Switch Series:
Table of Contents

Advertisement

TCP attack protection configuration

TCP attack protection overview

An attacker can attack the switch during the process of establishing a TCP connection. To prevent such an
attack, the switch provides the SYN Cookie feature.

Enabling the SYN cookie feature

As a general rule, the establishment of a TCP connection involves the following three handshakes.
The request originator sends a SYN message to the target server.
1.
After receiving the SYN message, the target server establishes a TCP connection in the
2.
SYN_RECEIVED state, returns a SYN ACK message to the originator, and waits for a response.
After receiving the SYN ACK message, the originator returns an ACK message, establishing the
3.
TCP connection.
Attackers may mount SYN Flood attacks during TCP connection establishment. They send a large number
of SYN messages to the server to establish TCP connections, but they never make any response to SYN
ACK messages. As a result, a large number of incomplete TCP connections are established, resulting in
heavy resource consumption and making the server unable to handle services normally.
The SYN Cookie feature can prevent SYN Flood attacks. After receiving a TCP connection request, the
server directly returns a SYN ACK message, instead of establishing an incomplete TCP connection. Only
after receiving an ACK message from the client can the server establish a connection, and then enter the
ESTABLISHED state. In this way, incomplete TCP connections could be avoided to protect the server
against SYN Flood attacks.
Follow these steps to enable the SYN Cookie feature:
To do...
Enter system view
Enable the SYN Cookie feature
NOTE:
With the SYN Cookie feature enabled, only the MSS, is negotiated during TCP connection
establishment, instead of the window's zoom factor and timestamp.

Displaying and maintaining TCP attack protection

To do...
Display current TCP connection state
Use the command...
system-view
tcp syn-cookie enable
Use the command...
display tcp status [ | { begin | exclude |
include } regular-expression ]
248
Remarks
Required
Enabled by default.
Remarks
Available in any view

Advertisement

Table of Contents
loading

Table of Contents