Radware Alteon Application Manual page 206

Application switch operating system
Hide thumbs Also See for Alteon:
Table of Contents

Advertisement

Alteon Application Switch Operating System Application Guide
Server Load Balancing
Configuring Delayed Binding
To configure delayed binding
>> # /cfg/slb/virt <virtual server number> /service <service type> /dbind
Current delayed binding: disabled
Enter new delayed binding [d/e/f]:e
Note:
Enable delayed binding without configuring any HTTP SLB processing or persistent binding
types.
To configure delayed binding for cache redirection, see
page
461.
Detecting SYN Attacks
In Alteon, SYN attack detection is enabled by default whenever delayed binding is enabled. SYN
attack detection includes the following capabilities:
Provides a way to track half open connections
Activates a trap notifying that the configured threshold has been exceeded
Monitors DoS attacks and proactively signals alarm
Provides enhanced security
Improves visibility and protection for DoS attacks
The probability of a SYN attack is higher if excessive half-open sessions are generated on Alteon.
Half-open sessions show an incomplete three-way handshake between the server and the client. You
can view the total number of half-open sessions from the
To detect SYN attacks, Alteon keeps track of the number of new half-open sessions for a set period.
If the value exceeds the threshold, then a syslog message and an SNMP trap are generated.
You can change the default parameters for detecting SYN attacks in the
menu. You can specify how frequently you want to check for SYN attacks, from two seconds to one
minute, and modify the default threshold representing the number of new half-open sessions per
second.
Force Proxy Using the Application Service Engine
Alteon provides various application layer services which require a full TCP proxy behavior. Some of
these capabilities include SSL offloading, HTTP caching and compression, HTTP modifications, TCP
optimizations, and more. To facilitate these functionalities, Alteon includes a module named
Application Service Engine.
The Application Service Engine is a full TCP proxy which performs delayed binding of connections,
during which it can optimize TCP behavior, intercept client requests and server responses to modify
them, and so on. In some cases, the proxy behavior itself may be required even without the use of
any other application service. For this purpose, you can set delayed binding to Force Proxy mode. In
206
Delayed Binding for Cache Redirection,
/stat/slb/layer7/maint
/cfg/slb/adv/synatk
Document ID: RDWR-ALOS-V2900_AG1302
menu.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents