This URL updates the TCP settings on the Sensor.
Resource URL
PUT /sensor/<sensor_id>/tcpsettings
Request Parameters
URL Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| sensor_id | Sensor id | Number | Yes |
Payload Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| TCPSettings | The TCP settings on the Sensor | Object | Yes |
Details of fields in TCPSettings:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| tcpParameter | The parameters of TCP settings | Object | No |
Details of fields in tcpParameter:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| supportedUDPFlows | The supported UDP flows | Number | No |
| tcbInactivityTimesInMinutes | The TCP inactivity timer(minutes) | Number | No |
| tcpSegmentTimerInSeconds | The TCP segment timer(seconds) | Number | No |
| tcp2MSLTimerInSeconds | The TCP 2MSL timer (seconds) | Number | No |
| coldStartTimeInMinutes | The cold start time (minutes) | Number | No |
|
coldStartAckScan
AlertDiscardIntervalInMinutes |
The cold start ack scan alert discard Interval (minutes) | Number | No |
| coldStartDropAction | The cold start drop action. The value can be:
|
String | No |
| tcpFlowViolation | The TCP flow violation. The value can be:
|
String | No |
|
unsolicitedUDP
PacketTimeOutInSeconds |
The unsolicited UDP packets timeout (seconds) | Number | No |
| Normalization | The normalization. The value can be:
|
String | No |
| tcpOverlapOption | The TCP overlap option. The value can be:
|
String | No |
| synCookie | The SYN cookie data | Object | No |
|
resetUnfinished3Way
HandshakeConnection |
The reset unfinished 3 way handshake connection. The value can be:
|
String | No |
| dnsSinkholingTimeToLive | DNS sinkholing time to live | Number | No |
| dnsSinkholingIPAddress | DNS sinkholing IP address | String | No |
Details of fields in synCookie:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| synCookieOption | The SYN cookie option. The value can be:
|
String | Yes |
| inboundThresholdValue | The inbound threshold value | Number | No |
| outboundThresholdValue | The outbound threshold value | Number | No |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| status | Set to 1 if the operation was successful | Number |
Example
Request
PUT https://<NSM_IP>/sdkapi/sensor/1002/tcpsettings
Payload
{
"tcpParameter": {
"supportedUDPFlows": 100,
"tcbInactivityTimesInMinutes": 10,
"tcpSegmentTimerInSeconds": 10,
"tcp2MSLTimerInSeconds": 10,
"coldStartTimeInMinutes": 0,
"coldStartAckScanAlertDiscardIntervalInMinutes": 0,
"coldStartDropAction": "FORWARD_FLOWS",
"tcpFlowViolation": "PERMIT_OUT_OF_ORDER",
"unsolicitedUDPPacketTimeOutInSeconds": 10,
"normalization": "OFF",
"tcpOverlapOption": "NEW_DATA",
"synCookie": {
"synCookieOption": "INBOUND_ONLY",
"inboundThresholdValue": 14112,
"outboundThresholdValue": 10000
},
"dnsSinkholingTimeToLive": 720,
"dnsSinkholingIPAddress": "1.1.1.1"
"resetUnfinished3WayHandshakeConnection": "SET_FOR_DOS_ATTACK_TRAFFIC_ONLY"
}
}
Response
{
"status": 1
}
Error Information
Following error codes are returned by this URL:
| No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 404 | 1106 | Invalid Sensor |
| 2 | 400 | 1124 | The Sensor is inactive |
| 3 | 400 | 5501 | Supported UDP flows should be between <value> |
| 4 | 400 | 5502 | TCB inactivity time should be between 10 and 1200 |
| 5 | 400 | 5503 | TCP segment timer should be between 10 and 120 |
| 6 | 400 | 5504 | TCP 2MSL should be between 3 and 120 and the value should be 3 sec more than the correlation time for signatures. Correlation time is <value> |
| 7 | 400 | 5505 | Cold start time should be between 0 and 10080 |
| 8 | 400 | 5506 | Cold start ack scan alert discard interval should be between 0 and 1440 |
| 9 | 400 | 5507 | Unsolicited UDP packet timeout should be between 10 and 3600 |
| 10 | 400 | 5508 | Disable SYN cookie first before setting TCP flow violation to stateless inspection |
| 11 | 400 | 5509 | SYN cookie must be set to DISABLED when TCP flow violation is stateless inspection |
| 12 | 400 | 5510 | Cannot update SYN cookie when TCP flow violation is set to stateless inspection |
| 13 | 400 | 5515 | Syncookie threshold value should be between 0 and <value> |
| 14 | 400 | 5516 | Syncookie threshold value is mandatory |