A NetScaler T1 appliance defends against SYN flood attacks by using SYN cookies instead of maintaining half-open connections on the system memory stack. The appliance sends a cookie to each client that requests a TCP connection, but it does not maintain the states of half-open connections. Instead, the appliance allocates system memory for a connection only upon receiving the final ACK packet, or, for HTTP traffic, upon receiving an HTTP request. This prevents SYN attacks and allows normal TCP communications with legitimate clients to continue uninterrupted. Specific function is enabled by default without option to disable.
However, there is caveat as standard SYN cookies limit connections to the use of only eight Maximum Segment Size (MSS) values. If connection MMS does not match with any predefined value, it will pick up the next available lower value towards both client and server side.
The predefined TCP Maximum Segment Size (MSS) values are the following and can be configured through a new nsapimgr knob.
|
|
|
|
|
|
|
|
| 1460 |
1440 |
1330 |
1220 |
956 |
536 |
384 |
128 |
The new MSS table:
-
Need not contain Jumbo-Frame support. Even though by default 8 values are reserved in the MSS table for jumbo frames, the table settings can be modified to include standard Ethernet-sized frames only.
-
Should have 16 values
-
Should have values in descending order
-
Should include 128 as the last value
If the new MSS table is valid, the table is stored and the old values are switched out at the SYN-cookie rotation time. Otherwise the new table returns an error. Changes are applied to new connections while existing connections preserve the old MSS table until the connections expire or are terminated.
To display the current MSS table in a NetScaler appliance, type the following command.
Command:
>shell
#nsapimgr -d mss_table
Example:
#nsapimgr -d mss_table
MSS table
{9176,9156,8192,7168,6144,4196,3072,2048,1460,1440,1330,1212,956,536,384,128}
Done.
To change the mss table, type the following command:
Command:
>shell
#nsapimgr -s mss_table=<16 comma seperated values>
Example:
#nsapimgr -ys mss_table=9176,9156,8192,7168,6144,4196,3072,2048,1460,1400,1330,1212,956,536,384,128
# nsapimgr -d mss_table
MSS table
{9176,9156,8192,7168,6144,4196,3072,2048,1460,1400,1330,1212,956,536,384,128}
Done.
An example using standard Ethernet-sized values is depicted below:
Example:
#nsapimgr -ys mss_table=1460,1440,1420,1400,1380,1360,1340,1320,1300,1280,1260,1212,956,536,384,128
# nsapimgr -d mss_table
MSS table
{1460,1440,1420,1400,1380,1360,1340,1320,1300,1280,1260,1212,956,536,384,128}
Done.
To make this change permanent even after the NetScaler appliance restarts, include the command #nsapimgr -ys mss_table=<16 comma seperated values> in the "/nsconfig/rc.netscaler" file. If the "rc.netscaler" file doesn't exist, create it under the "/nsconfig" folder, and then append the command.