12.07.2015 Views

BROCADE IP PRIMER

BROCADE IP PRIMER

BROCADE IP PRIMER

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

ServerIronThe Brocade ServerIrondoes eventually send an ACK (within the time allotted), the ServerIron forwardsit. The real server sees the ACK as a duplicate, and ignores it. If no ACK comeswithin the time allowed, the ServerIron sends a TCP RST to the real server toterminate the session.On a chassis or a stackable, this protection is configured the same way. Youmay either enable it globally, or on an individual port basis. Either way, it mustfirst be defined in the Global config:SLB-ServerIron#conf tSLB-ServerIron(config)#server syn-def 6This command enables SYN-Defense (or TCP SYN Protection on stackables)globally, for all TCP sessions in the device. It has set the timer for six seconds.This is how long the ServerIron will wait from the time the TCP SYN/ACK is sentuntil it resets the session. The timer may be anything from 0 to 16 seconds. Ifit is set to 0, the protection is disabled.If you are using a ServerIron chassis model, there may be circumstances inwhich you want to enable SYN-Defense, but you don't want the ServerIron tosend the final ACK on behalf of the client. This can be disabled with the followingcommand:SLB-ServerIron#conf tSLB-ServerIron(config)#server syn-def-dont-send-ackThere may be situations where you only want this protection applied to trafficon certain interfaces. In this case, you must first configure it globally first (aswe did above). Then:SLB-ServerIron#conf tSLB-ServerIron(config)#server syn-def 6SLB-ServerIron(config)#int e 1SLB-ServerIron(config-if-1)#syn-defSLB-ServerIron(config)#int e 5SLB-ServerIron(config-if-5)#syn-defIn this example, we've enabled the protection, but we've confined it to trafficthat is flowing through e 1 and e 5. The interfaces defined will still use theglobal setting (six seconds, in this example) as its timer.Another method to defend against SYN attacks is called SYN-Guard.AttackerSYN-Guard TMServerIronServerTCP SYNTCP SYN/ACK(no reply)TCP RSTBrocade <strong>IP</strong> Primer 331

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!