You can customize the TCP parameter checks for a Sensor using the Protocol Settings page. TCP parameters are effective only when the configured Sensor is deployed in inline mode.
Task
- Click the Devices tab.
- Select the domain from the Domain drop-down list.
- On the left pane, click the Devices tab.
- Select the device from the Device drop-down list.
- Select Setup → Advanced → Protocol Settings.
-
To edit a parameter, type or select a new value and click
Update for that parameter.
To restore the default values, scroll down to the bottom of the page and click Restore.
Caution
To prevent system errors, Trellix recommends that only users with detailed knowledge of TCP configure these settings.
Option Definition TCB Inactivity Timer If a TCB (Transmission Control Block) does not receive any packets before this timer expires, the TCB is marked inactive. TCBs are limited, therefore inactive TCBs can be allocated to new session (or connections). TCP Segment Timer Time to wait for the out of order segments to become ordered before dropping them. TCP 2MSL Timer Time to wait for a connection control block to be freed before it is torn down. The maximum segment lifetime (MSL) is the amount of time that a packet can be in transit on the network. Cold Start Time When Sensor is first turned on, it does not have any flow information. Set the Cold Start Time to specify a window of time for the Sensor to allow packets without established control blocks to pass through. Cold Start Ack Scan Alert Discard Interval After a cold start, the Sensor will not alert for Ack Sweeps or Ack Scans until this interval (timer) expires. Cold Start Drop Action When starting a Sensor for the first time, you can decide to allow (forward) or drop all packets that do not have a flow control block recognized by the Sensor. - Forward Flows
- Drop Flows
TCP Flow Violation - Permit — For out-of-order packets, the Sensor holds packets up to (TCP Segment Timer) seconds for re-assembly before performing inspection. If re-assembly fails because some packets are still missing, the Sensor simply forwards the traffic. When the TCP state is not established, the Sensor allows the packets to pass through.
- Deny — For out-of-order packets, the Sensor holds packets up to (TCP Segment Timer) seconds for re-assembly before performing inspection. If re-assembly fails because some packets are still missing, the Sensor drops the traffic. When the TCP state is not established, the Sensor drops the traffic.
- Permit out-of-order — The Sensor allows out-of-order packets to continue to transmit without processing. When the TCP state is not established, the Sensor allows the packets to pass through.
- Deny no TCB (Deny if State Not Established) — For out-of-order packets, the Sensor holds packets up to (TCP Segment Timer) seconds for re-assembly before performing inspection. If re-assembly fails because some packets are still missing, the Sensor simply forwards the traffic. When the TCP state is not established, the Sensor drops the traffic.
- Stateless Inspection — The Sensor detects attacks without requiring a valid TCP state. This option should be used only when Sensors are placed in a network where the Sensors do not see all packets of a TCP flow like in an asymmetric network configuration. Stateless Inspection can only be implemented in IPv4 packets.
When Stateless Inspection is enabled:
- Firewall and syn cookie protection cannot be enabled.
- HTTP redirection to the Remediation Portal may or may not work depending on your network deployment scenario for example, in a setup where SYN+ACK packets cannot be sent from the Sensor to the client.
Normalization On/Off Option Sensor performs TCP/IP/ICMP options checking to normalize the traffic. TCP Overlap Option TCP segments may overlap, thus you need to select which data to process: the newer data or the older data. - New Data — Common for Linux, Solaris, HP_UX, and FreeBSD systems
- Old Data — Common for Windows systems
SYN Cookie SYN cookies are used to counter SYN flood attacks. With SYN cookies enabled, whenever a new connection request arrives at a server, the server sends back a SYN+ACK with an Initial Sequence Number (ISN) uniquely generated using the information present in the incoming SYN packet and a secret key. If the connection request is from a legitimate host, the server gets back an ACK from the host. - Disabled — Disable SYN cookies.
- Inbound Only — Use SYN cookies for inbound traffic only.
- Outbound Only — Use SYN cookies for outbound traffic only.
- Both Inbound and Outbound — Use SYN cookies for inbound and outbound traffic.
Caution
- SYN cookie feature is not enabled by default.
- Do not enable SYN cookies when passing MPLS traffic through a Sensor.
- Sensors using SYN cookie settings must be in inline mode. If you don't have any ports in inline mode, configure at least one port to be inline.
- A Sensor will only see a packet once on any interface. However, if a Sensor is monitoring an interface containing VLAN-tagged traffic, a separate subinterface must be configured for each VLAN to ensure a packet is not seen more than once.
Inbound Threshold Value The number of incomplete SYNs beyond which SYN cookies have to be enabled for an incoming connection. Outbound Threshold Value The number of incomplete SYNs beyond which SYN cookies have to be enabled for an outgoing connection. Reset unfinished 3 way handshake connection When enabled, automatically sends a TCP RST to the source when the TCP SYN timer has expired for a connection. - Disabled
- Set for all traffic
- Set for DoS attack traffic only
Supported UDP Flows Number of UDP transmissions allowed per Sensor. This varies for each Sensor model. The default number of UDP transmissions that is supported is displayed, which you can change. See the NS-series Sensor capacity by model number for the default and maximum number of supported UDP flows for each Sensor model.
Unsolicited UDP Packets Timeout Time to wait to receive a response packet for a sent packet. If time not met, the packet is dropped. DNS Sinkholing Time-To-Live (TTL) The TTL to be included in the crafted DNS response packets sent by the Sensor. Note
The default and the maximum values are 720 minutes.
DNS Sinkholing IP Address: The IP address to which the bot traffic is sinkholed. Note
The default value is the loop back IP address (127.0.0.1 for A records and ::1 for quad-A records present in the actual DNS response). You can configure an IPv4 address for the bot to send the bot traffic to that server. You cannot configure an IPv6 address as a sinkhole server IP address.
FTP Acceleration Set the fast forward FTP data flows feature.