HP MSR Series Configuration Manual page 501

Hpe flexnetwork msr router series
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Figure 146 Safe reset/SYN cookie mode application
TCP proxy in safe reset mode
As shown in
1.
After receiving a SYN packet destined for a protected server, the TCP proxy sends back a SYN
ACK packet with an invalid sequence number.
2.
If the TCP proxy receives an RST packet from the client, the client is verified as legitimate.
3.
The TCP proxy adds the client's IP address to the trusted IP list and starts forwarding TCP
packets from the client to the server.
The safe reset mode requires that TCP clients use the standard TCP protocol suite. Legitimate
clients that use non-standard TCP protocol suites will be verified as illegitimate by the TCP proxy.
With client verification, the TCP connection establishment takes more time than normal TCP
connection establishment.
Figure 147 TCP proxy in safe reset mode
TCP client
(2) SYN ACK (invalid sequence
(4) SYN (retransmitting)
TCP proxy in SYN cookie mode
As shown in
follows:
1.
After receiving a SYN packet from a client to a protected server, the TCP proxy sends back a
SYN ACK packet with the window size 0. If the client responds with an ACK packet, the client is
verified as legitimate. The proxy device establishes a TCP connection with the client.
2.
The TCP proxy device establishes a connection with the server through a new three-way
handshake that has a different window size. This connection uses a different sequence number
from the connection between the client and proxy device.
In SYN cookie mode, the TCP proxy is the server proxy that communicates with clients and the client
proxy that communicates with server. Choose this mode when the following requirements are met:
The TCP proxy device is deployed on the key path that passes through the ingress and egress
of the protected server.
All packets exchanged between clients and server pass through the TCP proxy device.
Figure
147, the safe reset mode functions as follows:
TCP proxy
(1) SYN
number)
(3) RST
(6) SYN ACK
(7) ACK
Figure
148, SYN cookie mode requires two TCP connections to be established as
TCP server
(5) SYN (forwarding)
(8) ACK (forwarding)
486

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents