Skip to main content
sims
Explorer II
August 7, 2016
Solved

bad syn packets

  • August 7, 2016
  • 1 reply
  • 3931 views

Hi,

How  to reduce bad  syn rate to the minimum ?

 

Thanks

    Best answer by SteveDDoS_FTNT

    The system default is 500 SYNs/sec. You can manually change that Threshold per SPP down to 0 but I would not recommend it unless testing.  Make sure SPP Settings > General Tab has SYN Flood Mitigation direction inbound enabled and SPP Settings > TCP Tab has SYN Validation enabled.

    Make sure SPP Settings > General Tab has SYN Flood Mitigation direction inbound enabled and SPP Settings > TCP Tab has SYN Validation enabled.

    Even 500 SYNs/sec should not have much impact on your servers.  If small numbers of SYNs are affecting your servers, it might be slow attacks where you need to see if  SPP Settings > Aggressive Aging Feature Control > Track Slow Connections is enabled and in the Global Settings > Settings > Settings > Slow Connections is set to something other than "none" - "Moderate" is a good start.

     

    I'm assuming here you are asking how low you can set the detection of bad SYNs.  When the number of SYNs crosses the threshold the system attempts to validate the Sources of those SYNs using the algorithm defined in SPP Settings > SPP settings > General: SYN Cookie (recommended), ACK Cookie or SYN retransmission. If the SYN is real, the Source IP is added to a legitimate IP table but the first SYN is lost and the browser or client needs to send another SYN to start the connection.

     

    If you can explain the actual problem, it might be easier to find an answer.

    1 reply

    SteveDDoS_FTNT
    Staff
    Staff
    August 7, 2016

    The system default is 500 SYNs/sec. You can manually change that Threshold per SPP down to 0 but I would not recommend it unless testing.  Make sure SPP Settings > General Tab has SYN Flood Mitigation direction inbound enabled and SPP Settings > TCP Tab has SYN Validation enabled.

    Make sure SPP Settings > General Tab has SYN Flood Mitigation direction inbound enabled and SPP Settings > TCP Tab has SYN Validation enabled.

    Even 500 SYNs/sec should not have much impact on your servers.  If small numbers of SYNs are affecting your servers, it might be slow attacks where you need to see if  SPP Settings > Aggressive Aging Feature Control > Track Slow Connections is enabled and in the Global Settings > Settings > Settings > Slow Connections is set to something other than "none" - "Moderate" is a good start.

     

    I'm assuming here you are asking how low you can set the detection of bad SYNs.  When the number of SYNs crosses the threshold the system attempts to validate the Sources of those SYNs using the algorithm defined in SPP Settings > SPP settings > General: SYN Cookie (recommended), ACK Cookie or SYN retransmission. If the SYN is real, the Source IP is added to a legitimate IP table but the first SYN is lost and the browser or client needs to send another SYN to start the connection.

     

    If you can explain the actual problem, it might be easier to find an answer.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!