tcp-syn-defense (IDS MS-MPC)
Syntax
tcp-syn-defense;
Hierarchy Level
[edit services ids rule rule-name term term-name then]
Description
Close unestablished TCP connections and send a
TCP RST to the end host to clear the TCP states on it when the open-timeout
value at the [edit interfaces interface-name service-options]
hierarchy level expires. This provides protection
against TCP SYN flooding attacks. This statement can only be used
in IDS rules assigned to a service set on an MS-MPC.
Required Privilege Level
interface—To view this statement in the configuration.
interface-control—To add this statement to the configuration.
Release Information
Statement introduced in Junos OS Release 17.1.