Cisco IP TCP Intercept

About TCP Intercept

The TCP intercept feature implements software to protect TCP servers from TCP SYN-flooding attacks, which are a type of denial-of-service attack.

Set the TCP Intercept Mode

The TCP intercept can operate in either active intercept mode or passive watch mode. The default is intercept mode.

In intercept mode, the software actively intercepts each incoming connection request (SYN) and responds on behalf of the server with an ACK and SYN, then waits for an ACK of the SYN from the client. When that ACK is received, the original SYN is set to the server and the software performs a three-way handshake with the server. When this is complete, the two half-connections are joined.

In watch mode, connection requests are allowed to pass through the router to the server but are watched until they become established. If they fail to become established within 30 seconds (configurable with the ip tcp intercept watch-timeout command), the software sends a Reset to the server to clear up its state.

To set the TCP intercept mode, perform the following task in global configuration mode:

Task

Command
Set the TCP intercept mode. ip tcp intercept mode {intercept | watch}

Set the TCP Intercept Drop Mode

When under attack, the TCP intercept feature becomes more aggressive in its protective behavior. If the number of incomplete connections exceeds 1100 or the number of connections arriving in the last one minute exceeds 1100, each new arriving connection causes the oldest partial connection to be deleted. Also, the initial retransmission timeout is reduced by half to 0.5 seconds (so the total time trying to establish a connection is cut in half).

By default, the software drops the oldest partial connection. Alternatively, you can configure the software to drop a random connection. To set the drop mode, perform the following task in global configuration mode:

Task

Command
Set the drop mode. ip tcp intercept drop-mode {oldest | random}

Change the TCP Intercept Timers

By default, the software waits for 30 seconds for a watched connection to reach established state before sending a Reset to the server. To change this value, perform the following task in global configuration mode:

Task

Command
Change the time allowed to reach established state. ip tcp intercept watch-timeout seconds

 

By default, the software waits for 5 seconds from receipt of a reset or FIN-exchange before it ceases to manage the connection. To change this value, perform the following task in global configuration mode:

Task

Command
Change the time between receipt of a reset or FIN-exchange and dropping the connection. ip tcp intercept finrst-timeout seconds

 

By default, the software still manages a connection for 24 hours after no activity. To change this value, perform the following task in global configuration mode:

Task

Command
Change the time the software will manage a connection after no activity. ip tcp intercept connection-timeout seconds

Monitor and Maintain TCP Intercept

To display TCP intercept information, perform either of the following tasks in EXEC mode:

Task

Command
Display incomplete connections and established connections. show tcp intercept connections
Display TCP intercept statistics. show tcp intercept statistics

TCP Intercept Configuration Example

The following configuration defines extended IP access list 101, causing the software to intercept packets for all TCP servers on the 192.168.1.0/24 subnet:

ip tcp intercept list 101

!

access-list 101 permit tcp any 192.168.1.0 0.0.0.255

ip tcp intercept list TCP_INTERCEPT
ip tcp intercept connection-timeout 60
ip tcp intercept finrst-timeout 60
ip tcp intercept max-incomplete low 500
ip tcp intercept max-incomplete high 600
ip tcp intercept one-minute low 500
ip tcp intercept one-minute high 600
!
!
ip access-list extended TCP_INTERCEPT
 permit tcp any 192.168.4.0 0.0.0.15
 permit tcp any 192.168.2.0 0.0.0.7
 permit tcp any 192.168.6.0 0.0.0.7
 permit tcp any 192.168.11.0 0.0.0.7