Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: SRX 3K SYN proxy problem

$
0
0

Hello,

I'd suggest You familiarize Yourself with difference between SYN-FLOOD protection and SYN-ACk-ACK proxy protection

 

SYN-FLOOD:

http://www.juniper.net/techpubs/en_US/junos15.1x49/topics/concept/denial-of-service-network-syn-flood-attack-understanding.html

 B responds with SYN/ACK segments to these addresses and then waits for responding ACK segments. Because the SYN/ACK segments are sent to nonexistent or unreachable IP addresses, they never elicit responses and eventually time out

Meaning - with SYN-FLOOD, 3-way TCP HS never completes.

 

SYN-ACK-ACK proxy:

 

http://www.juniper.net/documentation/en_US/junos15.1x49/topics/concept/denial-of-service-firewall-syn-ack-ack-proxy-flood-attack-understanding.html

 

At this point, the initial three-way handshake is complete

Meaning - as above.

If You are only getting inbound SYNs, without ACKs, SYN-ACK-ACK proxy is useless.

HTH

Thx

Alex


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>