Community discussions

MikroTik App
 
User avatar
Charlie Whiskey
just joined
Topic Author
Posts: 24
Joined: Wed Nov 16, 2005 7:45 am

Syn flood protection - what's the best approach?

Fri Jan 13, 2006 9:34 am

Would RouterOS match a packet to the rule "tcp-flags=syn" if some other flags are set as well? Is using this rule an effective proof against syn floods? If so then is there a guide out there for figuring out how to set the optimum limit?
 
User avatar
sublimespot
newbie
Posts: 46
Joined: Sun Sep 11, 2005 2:00 am

Sun Jan 22, 2006 6:47 pm

On regular linux, enabling "syn cookies" can help a little in trying to keep the server alive during a dos attack. Usually a dos attack eats up all your available bandwidth. No software setting can fix that.