Radware Alteon Application Manual page 392

Application switch operating system
Hide thumbs Also See for Alteon:
Table of Contents

Advertisement

Alteon Application Switch Operating System Application Guide
Filtering and Traffic Manipulation
Any filter may be set to match against more than one TCP flag at the same time. If there is more
than one flag enabled, the flags are applied with a logical AND operator. For example, by setting
Alteon to filter SYN and ACK, Alteon filters all SYN-ACK frames.
Notes
TCP flag filters must be cache-disabled. Exercise caution when applying cache-enabled and
cache-disabled filters to the same port. For more information, see
Filters, page 362
.
With IPv6, TCP health checks end with an RST flag instead of FIN as in IPv4.
Configuring the TCP Flag Filter
By default, all TCP filter options are disabled. TCP flags are not inspected unless one or more TCP
options are enabled.
Consider the network as illustrated in
Figure 63: TCP Flag Filter Configuration Example
In this network, the Web servers inside the LAN must be able to transfer mail to any SMTP-based
mail server out on the Internet. At the same time, you want to prevent access to the LAN from the
Internet, except for HTTP.
SMTP traffic uses well-known TCP port 25. The Web servers originates TCP sessions to the SMTP
server using TCP destination port 25, and the SMTP server acknowledges each TCP session and data
transfer using TCP source port 25.
Creating a filter with the ACK flag closes one potential security hole. Without the filter, Alteon
permits a TCP SYN connection request to reach any listening TCP destination port on the Web
servers inside the LAN, as long as it originated from TCP source port 25. The server would listen to
the TCP SYN, allocate buffer space for the connection, and reply to the connect request. In some
SYN attack scenarios, this could cause the server's buffer space to fill, crashing the server or at least
making it unavailable.
A filter with the ACK flag enabled prevents external devices from beginning a TCP connection (with a
TCP SYN) from TCP source port 25. Alteon drops any frames that have the ACK flag turned off.
392
Figure 63 - TCP Flag Filter Configuration Example, page
Cached Versus Non-Cached
Document ID: RDWR-ALOS-V2900_AG1302
392.:

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents