- LG Software Innovations Two-Way Radio User Manual

1-35
Cisco SDM Express
OL-7141-04
Chapter 1 Cisco SDM Express
Supplementary Help
Set TCP Synwait Time
Cisco SDM Express sets the TCP synwait time to 10 seconds whenever possible.
The TCP synwait time is a value that is useful in defeating SYN flooding attacks,
a form of Denial-of-Service (DoS) attack. A TCP connection requires a
three-phase handshake to initially establish the connection. A connection request
is sent by the originator, an acknowledgement is sent by the receiver, and then an
acceptance of that acknowledgement is sent by the originator. After this
three-phase handshake is complete, the connection is complete and data transfer
can begin. A SYN flooding attack sends repeated connection requests to a host,
and never sends the acceptance of acknowledgements that complete the
connections, creating increasingly more incomplete connections at the host.
Because the buffer for incomplete connections is usually smaller than the buffer
for completed connections, this can overwhelm and disable the host. Setting the
TCP synwait time to 10 seconds causes the router to shut down an incomplete
connection after 10 seconds, preventing the buildup of incomplete connections at
the host.