DefensePro User Guide
Security Configuration
Document ID: RDWR-DP-V0602_UG1201
177
Configuring SYN Profiles for Network
Protection
SYN Profiles defend against SYN flood attacks.
During a SYN flood attack, the attacker sends a volume of TCP SYN packets requesting new TCP
connections without completing the TCP handshake, or completing the TCP handshake, but not
requesting data. This fills up the server connection queues, which denies service to legitimate TCP
users.
Before you configure a SYN profile, ensure the following:
•
The Session table Lookup Mode is Full Layer 4. For more information, see
.
•
SYN Flood protection is enabled and the global parameters are configured. You can change the
global settings. The SYN flood global settings apply to all the profiles on the device. For more
information, see
Configuring Global SYN Flood Protection, page 128
To configure a SYN profile
1. In the Configuration perspective Network Protection tab navigation pane, select SYN Profiles.
2. To add or modify a profile, do one of the following:
—
To add a profile, click the
(Add) button. Enter the profile name and click OK.
—
To edit a profile, double-click the entry in the table.
3. To add a SYN flood protection to the profile:
a. Right-click in the table and select Add New SYN Flood Protection.
b. From the Profile Name drop-down list, select the protection.
c. Click OK.
4. To define additional SYN flood protections for the profile, click Go To Protection Table.
Note:
A SYN profile should contain all the SYN flood protections that you want to apply in a
network-policy rule.
Table 91: SYN Profile Parameters
Parameter
Description
Profile Name
(Read-only) The name of the profile.
SYN Protection Table
Contains the protections to be applied for the selected profile.
To add a protection, in the table, right-click and select Add New SYN
Flood Protection. Select the protection name and click OK.
Note:
In each rule, you can use only one SYN profile. Therefore,
ensure that all the protections that you want to apply to a
rule are contained in the profile specified for that rule.
Go To Protection Table
Opens the Syn Protections dialog box in which you can add and
modify SYN protections.
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...