Configuring TCP SYN Flood Attack Screen
This topic describes how to configure detection of a TCP SYN flood attack.
A SYN flood occurs when a host is so overwhelmed by SYN segments initiating incomplete connection requests that it can no longer process legitimate connection requests.
Configure the security screen option and attach it to the untrustZone as follows:
[edit] user@host# set security screen ids-option untrustScreen tcp syn-flood user@host# tcp syn-flood attack-threshold number user@host# tcp syn-flood source-threshold number user@host# tcp syn-flood destination-threshold number user@host# tcp syn-flood timeout seconds user@host# set security screen ids-option untrustScreen alarm-without-drop user@host# set security zones security-zone untrustZone screen untrustScreen