Cisco IP TCP Intercept
About TCP Intercept
The TCP intercept feature implements software to protect TCP servers from TCP SYN-flooding attacks, which are a type of denial-of-service attack.
Set the TCP Intercept Mode
The TCP intercept can operate in either active intercept mode or passive watch mode. The default is intercept mode.
In intercept mode, the software actively intercepts each incoming connection request (SYN) and responds on behalf of the server with an ACK and SYN, then waits for an ACK of the SYN from the client. When that ACK is received, the original SYN is set to the server and the software performs a three-way handshake with the server. When this is complete, the two half-connections are joined.
In watch mode, connection requests are allowed to pass through the router to the server but are watched until they become established. If they fail to become established within 30 seconds (configurable with the ip tcp intercept watch-timeout command), the software sends a Reset to the server to clear up its state.
To set the TCP intercept mode, perform the following task in global configuration mode:
Set the TCP Intercept Drop Mode
When under attack, the TCP intercept feature becomes more aggressive in its protective behavior. If the number of incomplete connections exceeds 1100 or the number of connections arriving in the last one minute exceeds 1100, each new arriving connection causes the oldest partial connection to be deleted. Also, the initial retransmission timeout is reduced by half to 0.5 seconds (so the total time trying to establish a connection is cut in half).
By default, the software drops the oldest partial connection. Alternatively, you can configure the software to drop a random connection. To set the drop mode, perform the following task in global configuration mode:
Change the TCP Intercept Timers
By default, the software waits for 30 seconds for a watched connection to reach established state before sending a Reset to the server. To change this value, perform the following task in global configuration mode:
|
Task
|
Command
|
|---|---|
| Change the time allowed to reach established state. | ip tcp intercept watch-timeout seconds |
By default, the software waits for 5 seconds from receipt of a reset or FIN-exchange before it ceases to manage the connection. To change this value, perform the following task in global configuration mode:
|
Task
|
Command
|
|---|---|
| Change the time between receipt of a reset or FIN-exchange and dropping the connection. | ip tcp intercept finrst-timeout seconds |
By default, the software still manages a connection for 24 hours after no activity. To change this value, perform the following task in global configuration mode:
|
Task
|
Command
|
|---|---|
| Change the time the software will manage a connection after no activity. | ip tcp intercept connection-timeout seconds |
Monitor and Maintain TCP Intercept
To display TCP intercept information, perform either of the following tasks in EXEC mode:
|
Task
|
Command
|
|---|---|
| Display incomplete connections and established connections. | show tcp intercept connections |
| Display TCP intercept statistics. | show tcp intercept statistics |
TCP Intercept Configuration Example
The following configuration defines extended IP access list 101, causing the software to intercept packets for all TCP servers on the 192.168.1.0/24 subnet:
ip tcp intercept list 101
!
access-list 101 permit tcp any 192.168.1.0 0.0.0.255
ip tcp intercept list TCP_INTERCEPT
ip tcp intercept connection-timeout 60
ip tcp intercept finrst-timeout 60
ip tcp intercept max-incomplete low 500
ip tcp intercept max-incomplete high 600
ip tcp intercept one-minute low 500
ip tcp intercept one-minute high 600
!
!
ip access-list extended TCP_INTERCEPT
permit tcp any 192.168.4.0 0.0.0.15
permit tcp any 192.168.2.0 0.0.0.7
permit tcp any 192.168.6.0 0.0.0.7
permit tcp any 192.168.11.0 0.0.0.7