Configuring Ace Behavior For A Segment That Exceeds The Maximum Segment Size; Setting The Maximum Number Of Tcp Syn Retries - Cisco 4700M Configuration Manual

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Configuring a Connection Parameter Map for TCP/IP Normalization and Termination
Configuring ACE Behavior for a Segment That Exceeds the
Maximum Segment Size

Setting the Maximum Number of TCP SYN Retries

Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
4-12
Chapter 4
You can configure the ACE behavior for a segment that exceeds the configured
maximum segment size (MSS) by using the exceed-mss command in connection
parameter map configuration mode. The syntax of this command is as follows:
exceed-mss {allow | drop}
The keywords are as follows:
allow—Permits segments that exceed the configured MSS
drop—(Default) Discards segments that exceed the configured MSS
For example, to configure the ACE to allow segments that exceed the MSS, enter:
host1/C1(config-parammap-conn)# exceed-mss allow
To reset the ACE behavior to the default of discarding segments that exceed the
MSS set by a peer, enter:
host1/C1(config-parammap-conn)# no exceed-mss allow
You can set the maximum number of attempts that the ACE makes to transmit a
TCP segment when initiating a Layer 7 connection by using the set tcp syn-retry
command in connection parameter map configuration mode. The syntax of this
command is as follows:
set tcp syn-retry number
The number argument is the number of SYN retries. Enter an integer from 1 to 15.
The default is 4.
For example, to set the maximum TCP SYN retries to 3, enter:
host1/C1(config-parammap-conn)# set tcp syn-retry 3
To reset the TCP SYN retries to the default value of 4, enter:
host1/C1(config-parammap-conn)# no set tcp syn-retry
Configuring TCP/IP Normalization and IP Reassembly Parameters
OL-16202-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents