Defense against TCP Denial of Service Attacks on ICX 8100 and ICX 8200 Devices

Commands are available on RUCKUS ICX 8100 and ICX 8200 devices to rate limit TCP control traffic or to drop specific kinds of irregular TCP SYN control packets.

Rate Limiting TCP Control Traffic

Use the ip tcp burst-max command as shown to limit TCP control traffic flow. Valid values are 125 through 100000 packets per second.

The following example limits the rate of TCP SYN control packets to 1000 packets per second.

device# configure terminal
device(config)# ip tcp burst-max 1000

The command can also be used on a specific interface. The following example limits TCP SYN control packets to 125 packets per second on port 1/2/1.

device# configure terminal
device(config)# interface ethernet 1/2/1
device(config-if-e1000-1/2/1)# ip tcp burst-max 125

Dropping Irregular TCP Control Packets

On ICX 8100 and ICX 8200 devices, the following commands can be entered in global configuration mode as shown to drop suspect, malformed TCP control packets that may indicate a DOS attack. The commands can be configured on the same device as needed. To drop all malformed TCP control packets in this set, use the ip tcp tcp-all command.

The following example drops IPv4 and IPv6 TCP control packets sent using the MAC multicast mechanism.

device(config)# ip tcp over-mac-multicast

The following example drops TCP control packets with all flags set to zero.

device(config)# ip tcp zero-flags

The following example drops TCP control packets with both the SYN and URG-PSH flags set.

device(config)# ip tcp fin-urg-psh

The following example drops TCP control packets with both the SYN and FIN flags set.

device(config)# ip tcp syn-fin

The following example drops TCP control packets with both the SYN and RST flags set.

device(config)# ip tcp syn-rst

The following example drops TCP control packets with the source or destination port set to zero.

device(config)# ip tcp port-zero

The following example drops all malformed TCP control packets in this set.

device(config)# ip tcp tcp-all