ip tcp burst-normal

Configures the threshold values for TCP SYN packets that are targeted at the router itself or that pass through an interface.
Syntax
ip tcp burst-normal threshold-value burst-max max-value lockup time
no ip tcp burst-normal threshold-value burst-max max-value lockup time
Command Default

The threshold value is not configured.

Parameters
threshold-value
Configures the allowable number of TCP SYN packets per second in normal burst mode. Valid values are from 30 through 16,000,000.
burst-max max-value
Specifies the number of packets per second in maximum burst mode. Valid values are from 30 through 16,000,000.
lockup time
Configures the lockup period in seconds. Valid values are from 1 through 10,000 seconds.
Modes

Global configuration mode

Interface configuration sub-mode

VLAN configuration sub-mode

Usage Guidelines

Note: This command is not supported for ICX 8100 and ICX 8200 devices.

In a TCP SYN attack, an attacker floods a host with TCP SYN packets that have random source IP addresses. For each of these TCP SYN packets, the destination host responds with a SYN ACK packet and adds information to the connection queue. However, because the source host does not exist, no ACK packet is sent back to the destination host, and an entry remains in the connection queue until it ages out (after approximately one minute). If the attacker sends enough TCP SYN packets, the connection queue can fill up, and service can be denied to legitimate TCP connections.

To protect against TCP SYN attacks, you can configure the device to drop TCP SYN packets when excessive packets are encountered. You can set threshold values for TCP SYN packets that are targeted at the router itself or that pass through an interface, and drop them when the thresholds are exceeded.

If the interface is part of a VLAN that has a router VE, you must configure TCP SYN attack protection at the VE level. When TCP SYN attack protection is configured at the VE level, it will apply to routed traffic only. It will not affect switched traffic.

Note: You must configure VLAN information for the port before configuring TCP SYN attack protection. You cannot change the VLAN configuration for a port on which TCP SYN attack protection is enabled.
Note: This command is available at the global configuration level. This command is supported on Ethernet and Layer 3 interfaces.

The rate of incoming TCP SYN packets is measured and compared to the threshold values as follows:

  • If the number of TCP SYN packets exceeds the burst-normal value, the excess TCP SYN packets are dropped.
  • If the number of TCP SYN packets exceeds the burst-max value, all TCP SYN packets are dropped for the number of seconds specified by the lockup value. When the lockup period expires, the burst counter is reset and measurement is restarted.

The no form of the command removes the threshold values set for TCP SYN packets.

Examples

The following example sets the threshold values for TCP SYN packets targeted at the router.

device(config)# ip tcp burst-normal 30 burst-max 100 lockup 300

The following example sets the threshold values for TCP SYN packets received on interface 1/1/1.

device(config)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# ip tcp burst-normal 30 burst-max 100 lockup 300

The following example sets the threshold values for TCP SYN packets received on VLAN 23.

device(config)# vlan 23
device(config-vlan-23)# ip tcp burst-normal 5000 burst-max 10000 lockup 300