Why is tcp_syncookies off by default?

This is a discussion on Why is tcp_syncookies off by default? within the Linux Security forums, part of the System Security and Security Related category; The responses to the DoS posts here say to echo 1 >/proc/sys/net/ipv4/tcp_syncookies. Why is it ...


Go Back   Usenet Forums > System Security and Security Related > Linux Security

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 08-24-2004
buck
 
Posts: n/a
Default Why is tcp_syncookies off by default?

The responses to the DoS posts here say to
echo 1 >/proc/sys/net/ipv4/tcp_syncookies.

Why is it not already 1? Is there some drawback/caveat/whatever?

buck

Reply With Quote
  #2 (permalink)  
Old 08-24-2004
Jem Berkes
 
Posts: n/a
Default Re: Why is tcp_syncookies off by default?

> The responses to the DoS posts here say to
> echo 1 >/proc/sys/net/ipv4/tcp_syncookies.
>
> Why is it not already 1? Is there some drawback/caveat/whatever?


Google tells all. There are potential problems, such as denying legitimate
connections on a truly busy enterprise server.

Enabling ecn (explicit congestion notification, tcp_ecn) is also a good
idea, but it's not default because it tends to break things on occasion. A
sysadmin should be knowledgeable about these options and apply them when
appropriate. Turning on tcp_syncookies during an attack is a Good Idea.

--
Jem Berkes
http://www.sysdesign.ca/
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 08:53 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0