Timers config comparison between DoS for TLS settings
Hello every one,
We have been reviewing configuration details for TLS and found that there are several parameters for DoS prevention for de Acme Packet NN-4500 SBC to discard inactive TCP connections that may keep stablish forever.
According to the literature:
In sip-config:
inactive-dynamic-conn—Enter the time in seconds after which the Net-Net SD tears down inactive dynamic TCP connections. Inactive is defined as not transporting any traffic. This protects against endpoints establishing TCP/TLS connections and then not sending messages. The default value is 32. The valid range is:
•Minimum—0
•Maximum—999999999
Note: Setting this parameter to 0 disables this parameter.
Because the Net-Net SBC first establishes a TCP connection, then the TLS connection it waits twice the value entered here after the initiation of a TLS connection before tearing down the connection.