svcadm(8)을 검색하려면 섹션에서 8 을 선택하고, 맨 페이지 이름에 svcadm을 입력하고 검색을 누른다.
syncache(4)
MIBs for controlling TCP SYN caching The MIB is used to control
the TCP SYN caching in the system, which is intended to handle
SYN flood Denial of Service attacks. When a TCP SYN segment is
received on a port corresponding to a listen socket, an entry is
made in the and a SYN,ACK segment is returned to the peer. The
entry holds the TCP options from the initial SYN, enough state to
perform a SYN,ACK retransmission, and takes up less space than a
TCP control block endpoint. An incoming segment which contains
an ACK for the SYN,ACK and matches a entry will cause the system
to create a TCP control block with the options stored in the en‐
try, which is then released. The protects the system from SYN
flood DoS attacks by minimizing the amount of state kept on the
server, and by limiting the overall size of the provides a way to
virtually expand the size of the by keeping state regarding the
initial SYN in the network. Enabling sends a cryptographic value
in the SYN,ACK reply to the client machine, which is then re‐
turned in the client's ACK. If the corresponding entry is not
found in the but the value passes specific security checks, the
connection will be accepted. This is only used if the is unable
to handle the volume of incoming connections, and a prior entry
has been evicted from the cache. have a certain number of disad‐
vantages that a paranoid administrator may wish to take note of.
Since the TCP options from the initial SYN are not saved, they
are not applied to the connection, precluding use of features
like window scale, timestamps, or exact MSS sizing. As the re‐
turning ACK establishes the connection, it may be possible for an
attacker to ACK flood a machine in an attempt to create a connec‐
tion. While steps have been taken to mitigate this risk, this
may provide a way to bypass firewalls which filter incoming seg‐
ments with the SYN bit set. To disable the and run only with set
to 1. The implements a number of variables in the branch of the
MIB. Several of these may be tuned by setting the corresponding
variable in the Size of the hash table, must be a power of 2.
Read-only, tunable via Limit on the number of entries permitted
in each bucket of the hash table. This should be left at a low
value to minimize search time. Read-only, tunable via Limit on
the total number of entries in the Defaults to may be set lower
to minimize memory consumption. Read-only, tunable via Maximum
number of times a SYN,ACK is retransmitted before being dis‐
carded. The default of 3 retransmits corresponds to a 45 second
timeout, this value may be increased depending on the RTT to
client machines. Tunable via Number of entries present in the
(read-only). Statistics on the performance of the may be ob‐
tained via which provides the following counts: Entries success‐
fully inserted in the SYN,ACK retransmissions due to a timeout
expiring. Incoming SYN segment matching an existing entry. SYNs
dropped because SYN,ACK could not be sent. Successfully com‐
pleted connections. Entries dropped for exceeding per-bucket
size. Entries dropped for exceeding overall cache size. RST
segment received. Entries dropped due to maximum retransmissions
or listen socket disappearance. New socket allocation failures.
Entries dropped due to bad ACK reply. Entries dropped due to
ICMP unreachable messages. Failures to allocate new entry. Con‐
nections created from segment containing ACK. The existing im‐
plementation first appeared in The original concept of a origi‐
nally appeared in and was later modified by then further extended
here. The code and manual page were written by