syncache(4) 맨 페이지 - 윈디하나의 솔라나라

개요

섹션
맨 페이지 이름
검색(S)

syncache(4)

MIBs  for  controlling TCP SYN caching The MIB is used to control
the TCP SYN caching in the system, which is  intended  to  handle
SYN  flood  Denial of Service attacks.  When a TCP SYN segment is
received on a port corresponding to a listen socket, an entry  is
made  in  the and a SYN,ACK segment is returned to the peer.  The
entry holds the TCP options from the initial SYN, enough state to
perform a SYN,ACK retransmission, and takes up less space than  a
TCP  control  block endpoint.  An incoming segment which contains
an ACK for the SYN,ACK and matches a entry will cause the  system
to  create a TCP control block with the options stored in the en‐
try, which is then released.  The protects the  system  from  SYN
flood  DoS  attacks by minimizing the amount of state kept on the
server, and by limiting the overall size of the provides a way to
virtually expand the size of the by keeping state  regarding  the
initial SYN in the network.  Enabling sends a cryptographic value
in  the  SYN,ACK  reply  to the client machine, which is then re‐
turned in the client's ACK.  If the corresponding  entry  is  not
found  in  the but the value passes specific security checks, the
connection will be accepted.  This is only used if the is  unable
to  handle  the volume of incoming connections, and a prior entry
has been evicted from the cache.  have a certain number of disad‐
vantages that a paranoid administrator may wish to take note  of.
Since  the  TCP  options from the initial SYN are not saved, they
are not applied to the connection,  precluding  use  of  features
like  window  scale, timestamps, or exact MSS sizing.  As the re‐
turning ACK establishes the connection, it may be possible for an
attacker to ACK flood a machine in an attempt to create a connec‐
tion.  While steps have been taken to mitigate  this  risk,  this
may  provide a way to bypass firewalls which filter incoming seg‐
ments with the SYN bit set.  To disable the and run only with set
to 1.  The implements a number of variables in the branch of  the
MIB.   Several of these may be tuned by setting the corresponding
variable in the Size of the hash table, must be  a  power  of  2.
Read-only,  tunable  via Limit on the number of entries permitted
in each bucket of the hash table.  This should be left at  a  low
value  to  minimize search time.  Read-only, tunable via Limit on
the total number of entries in the Defaults to may be  set  lower
to  minimize  memory consumption.  Read-only, tunable via Maximum
number of times a SYN,ACK  is  retransmitted  before  being  dis‐
carded.   The default of 3 retransmits corresponds to a 45 second
timeout, this value may be increased  depending  on  the  RTT  to
client  machines.   Tunable  via Number of entries present in the
(read-only).  Statistics on the performance of  the  may  be  ob‐
tained  via which provides the following counts: Entries success‐
fully inserted in the SYN,ACK retransmissions due  to  a  timeout
expiring.  Incoming SYN segment matching an existing entry.  SYNs
dropped  because  SYN,ACK  could  not be sent.  Successfully com‐
pleted connections.  Entries  dropped  for  exceeding  per-bucket
size.   Entries  dropped  for  exceeding overall cache size.  RST
segment received.  Entries dropped due to maximum retransmissions
or listen socket disappearance.  New socket allocation  failures.
Entries  dropped  due  to  bad ACK reply.  Entries dropped due to
ICMP unreachable messages.  Failures to allocate new entry.  Con‐
nections created from segment containing ACK.  The  existing  im‐
plementation  first  appeared in The original concept of a origi‐
nally appeared in and was later modified by then further extended
here.  The code and manual page were written by









맨 페이지 내용의 저작권은 맨 페이지 작성자에게 있습니다.
RSS ATOM XHTML 5 CSS3