syn flooding

From: john (john_g123_5@yahoo.com)
Date: 01/18/02


From: john_g123_5@yahoo.com (john)
Date: 18 Jan 2002 11:05:02 -0800

question is about the syn flooding attack and how
firewalls prevent or save the protected servers
from it.

But question is that the firewall itself will also be trying
to contact the source or originator of the packet. and
if there are number of such packets (SYN packets) then
the firewall itself would also be overwhelmed. the
difference being that the servers protected by the
firewall will be saved. But what about the firewall itself ?

in summary, if a syn flood attack is launched on a
server which is protected by a firewall, then the firewall
would itself need to keep track of each connection attempted,
try to connect back to the client etc etc. if connection
fails then the session is dropped. So what about the
overwhelming of the firewall itself ?



Relevant Pages