Limit half-open TCP connections
Forcepoint Security Engine can track and maintain the number of half-open TCP connections, and the administrator can define a limit of the number of such connections (either for the Security Engine as a whole or for a specific rule).
When the Security Engine detects that the threshold has been exceeded, the Security Engine denies additional SYN packets. The Security Engine will expire such half-open TCP connections after fifteen seconds by default, and the administrator can change this default by configuring the TCP syn ack seen timeout.
If a half-open TCP connection limit is not configured the number of concurrent half-open connections is limited only by the TCP timeouts and the concurrent connection capacity of the Security Engine appliance.
To limit the number of half-open TCP connections, define the properties in the Engine Editor: