如何使用 Windows 防火墙或任何其他第三方防火墙阻止 Windows Server 2003 上的 syn Flood 攻击?
答案1
查看 MSDN 了解如何强化 TCP/IP 堆栈
Enable SYN Attack Protection
The named value to enable SYN attack protection is located beneath the registry key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TcpIp\Parameters.
Value name: SynAttackProtect
Recommended value: 2
Valid values: 0, 1, 2
Description: Causes TCP to adjust retransmission of SYN-ACKS. When you configure this value the connection responses timeout more quickly in the event of a SYN attack. A SYN attack is triggered when the values of TcpMaxHalfOpen or TcpMaxHalfOpenRetried are exceeded.