TCP Flags Filter
TCP SYN cookies filter is unavailable in
gate mode,
and the tcp_flags filter is intended to be used instead in this mode.
That is a simple TCP rate-limiting filter that can be enabled as follows:
tcp_flags [syn | rst];
In host mode the syn rate limit can be combined with
TCP SYN cookies. The rate limit is applied before SYN
cookies, so it bounds how many SYNs per second the cookie mechanism handles.
See Combining with the TCP SYN rate limit
for sizing guidance.
The filter supports the syn and rst attributes. It operates by rate-limiting
all TCP segments that has carry the corresponding TCP flags (SYN or RST).
Example configuration:
tcp_flags syn : ratelimit=default_ratelimit;
Patch example:
tcp_flags/del rst;