Limit half-open TCP connections

Forcepoint Security Engine can track and maintain the number of half-open TCP connections, and the administrator can define a limit of the number of such connections (either for the Security Engine as a whole or for a specific rule).

When the Security Engine detects that the threshold has been exceeded, the Security Engine denies additional SYN packets. The Security Engine will expire such half-open TCP connections after fifteen seconds by default, and the administrator can change this default by configuring the TCP syn ack seen timeout.

If a half-open TCP connection limit is not configured the number of concurrent half-open connections is limited only by the TCP timeouts and the concurrent connection capacity of the Security Engine appliance.

To limit the number of half-open TCP connections, define the properties in the Engine Editor:

Steps

  1. On the Advanced Settings > DoS Protection branch, set Rate-Based DoS Protection Mode to On, then set a value between 125 and 100000 for the Limit for Half-Open TCP Connections option.
    The limit applies per destination IP address. This option is enabled for all permitted traffic on the Security Engine, but can be overridden for some traffic in the Access rule options in a Engine Policy.
  2. (Optional) On the Advanced Settings > Idle Timeouts branch, click Add... to select TCP syn ack seen, and then click OK, then enter the value in seconds on the Idle Timeouts tab to change the default.