7.6.6 DDOS Prevention
7.6.6.1 SYN Flood Protection
SYN Flood Protection allows you to protect from attack that exploits part of the normal TCP three-way handshake
to consume resources on the targeted server and render it unresponsive. Essentially, with SYN flood DDoS, the offender
sends TCP connection requests faster than the targeted machine can process them, causing network saturation.
Enable SYN flood
protection
Makes router more resistant to SYN flood attacks.
Set rate limit (packets/second) for SYN packets above
which the traffic is considered a flood.
Set burst limit for SYN packets above which the traffic is
considered a flood if it exceeds the allowed rate.
Enable the use of SYN cookies(particular choices of initial
TCP sequence numbers by TCP servers).