This URL updates the TCP settings on the Sensor.
Resource URL
PUT /sensor/<sensor_id>/tcpsettings
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Sensor id | Number | Yes |
Payload Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| The TCP settings on the Sensor | Object | Yes |
Details of fields in TCPSettings:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| The parameters of TCP settings | Object | No |
Details of fields in tcpParameter:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| The supported UDP flows | Number | No |
| The TCP inactivity timer(minutes) | Number | No |
| The TCP segment timer(seconds) | Number | No |
| The TCP 2MSL timer (seconds) | Number | No |
| The cold start time (minutes) | Number | No |
| The cold start ack scan alert discard Interval (minutes) | Number | No |
| The cold start drop action. The value can be:
| String | No |
| The TCP flow violation. The value can be:
| String | No |
| The unsolicited UDP packets timeout (seconds) | Number | No |
| The normalization. The value can be:
| String | No |
| The TCP overlap option. The value can be:
| String | No |
| The SYN cookie data | Object | No |
| The reset unfinished 3 way handshake connection. The value can be:
| String | No |
| DNS sinkholing time to live | Number | No |
| DNS sinkholing IP address | String | No |
| HTTP2 flow allocation % | Number | Yes |
| Slow post timeout | Number | No |
| Slow post threshold frame size | Number | No |
| Slow post minimum number of streams | Number | No |
| Slow post minimum number of tiny frames | Number | No |
| Slow read timeout | Number | No |
| Slow read window size | Number | No |
| Slow read minimum number of streams | Number | No |
| HTTP2 decoded packets in attack packet log | Number | No |
| FTP acceleration | String | No |
Details of fields in synCookie:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| The SYN cookie option. The value can be:
| String | Yes |
| The inbound threshold value | Number | No |
| The outbound threshold value | Number | No |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| Set to 1 if the operation was successful | Number |
Example
Request
PUT https://<NSM_IP>/sdkapi/sensor/1002/tcpsettings
Payload
{
"tcpParameter": {
"supportedUDPFlows": 100,
"tcbInactivityTimesInMinutes": 10,
"tcpSegmentTimerInSeconds": 10,
"tcp2MSLTimerInSeconds": 10,
"coldStartTimeInMinutes": 0,
"coldStartAckScanAlertDiscardIntervalInMinutes": 0,
"coldStartDropAction": "FORWARD_FLOWS",
"tcpFlowViolation": "PERMIT_OUT_OF_ORDER",
"unsolicitedUDPPacketTimeOutInSeconds": 10,
"normalization": "OFF",
"tcpOverlapOption": "NEW_DATA",
"synCookie": {
"synCookieOption": "INBOUND_ONLY",
"inboundThresholdValue": 14112,
"outboundThresholdValue": 10000
},
"resetUnfinished3WayHandshakeConnection": "DISABLED",
"dnsSinkholingTimeToLive": 720,
"dnsSinkholingIPAddress": "127.0.0.1",
"http2FlowAllocPrcnt": 5,
"slowPostTimeout": 5,
"slowPostThresholdFrameSize": 10,
"slowPostMinStreamsCnt": 50,
"slowPostMinTinyFramesCnt": 1,
"slowReadTimeout": 60,
"slowReadWindowSize": 10,
"slowReadMinStreamsCnt": 50,
"http2DecodedPktInAtckPktLogFlag": "2",
"ftpAcceleration": "DISABLED"
}
}
Response
{
"status": 1
}
Error Information
Following error codes are returned by this URL:
No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 404 | 1106 | Invalid Sensor |
2 | 400 | 1124 | The Sensor is inactive |
3 | 400 | 5501 | Supported UDP flows should be between <value> |
4 | 400 | 5502 | TCB inactivity time should be between 10 and 1200 |
5 | 400 | 5503 | TCP segment timer should be between 10 and 120 |
6 | 400 | 5504 | TCP 2MSL should be between 3 and 120 and the value should be 3 sec more than the correlation time for signatures. Correlation time is <value> |
7 | 400 | 5505 | Cold start time should be between 0 and 10080 |
8 | 400 | 5506 | Cold start ack scan alert discard interval should be between 0 and 1440 |
9 | 400 | 5507 | Unsolicited UDP packet timeout should be between 10 and 3600 |
10 | 400 | 5508 | Disable SYN cookie first before setting TCP flow violation to stateless inspection |
11 | 400 | 5509 | SYN cookie must be set to DISABLED when TCP flow violation is stateless inspection |
12 | 400 | 5510 | Cannot update SYN cookie when TCP flow violation is set to stateless inspection |
13 | 400 | 5515 | Syncookie threshold value should be between 0 and <value> |
14 | 400 | 5516 | Syncookie threshold value is mandatory |
15 | 400 | 5520 | Slow post timeout should be between 5 and 30 |
16 | 400 | 5521 | Slow Post threshold framesize should be between 1 and 100 |
17 | 400 | 5522 | Slow Post min stream count should be between 50 and 100 |
18 | 400 | 5523 | Slow Post Min Tiny Frame count should be between 1 and 10 |
19 | 400 | 5524 | Slow Read Timeout should be between 30 and 300 |
20 | 400 | 5525 | Slow read window size should be between 1 and 100 |
21 | 400 | 5526 | Slow Read min streamcount should be between 50 and 100 |