Configuring Early Aging For Sessions; Setting The Maximum Number Of Sessions; Enabling Checksum Verification - HP 6600 Security Configuration Manual

Table of Contents

Advertisement

Configuring early aging for sessions

A device that does not support attack detection or attack protection is vulnerable to attacks on session
resources. If session resources are used up, the device cannot support normal forwarding services, for
example, NAT processing. To prevent such attacks, you can configure early aging for sessions.
After you configure early aging for sessions:
When the session ratio (the ratio of the number of established sessions to the session count
specification of the device) exceeds the upper threshold, the session aging time is shortened by a
specified time value. That is, sessions are aged out earlier.
When the session ratio equals or drops below the lower threshold, the session aging time is restored
to the normal values configured by the application aging-time or session aging-time command.
To configure early aging for sessions:
Step
1.
Enter system view.
2.
Set the time value to shorten
the session aging time.

Setting the maximum number of sessions

You can set the maximum number of sessions to limit the creation of sessions and reduce memory usage
by the session management module.
To set the maximum number of sessions:
Step
1.
Enter system view.
2.
Set the maximum number of
sessions.

Enabling checksum verification

To make sure session tracking is not affected by packets with checksum errors, you can enable checksum
verification for protocol packets. With checksum verification enabled, the session management feature
processes only packets with correct checksums, and packets with incorrect checksums will be processed
by other services based on the session management.
IMPORTANT:
Checksum verification might degrade the device performance. Enable it with caution.
Command
system-view
session early-ageout shorten-time
threshold-high
threshold-high-value threshold-low
threshold-low-value
Command
system-view
session max-entries max-entries
slot slot-number
456
Remarks
N/A
By default, the session aging time
is not shortened.
Remarks
N/A
The maximum number of sessions
depends on the device model, but
should not exceed the session
count specification of a device or a
card. For more information, see
product specifications.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hsr6600

Table of Contents