cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
237
Views
0
Helpful
1
Replies

PIX: Reccomendation on max_embryonic_connections?

abatson
Level 1
Level 1

By default the Static command doesn't impose any limit on the max. no. of SYN packets that can come thru the PIX. Because of a recent DoS attack, I need to enable this feature, but was wondering what different PIX administrators use for this value...

-Alex

1 Reply 1

scoclayton
Level 7
Level 7

It really depends on the limits of the operating system you are trying to protect. For instance, Windows can handle about 125 embryonic conns at any one time. Therefore, we usually recommend setting the max embryonic connections to something below 125 for Windows hosts - 110 is usually a good place to start. Other OS's can handle more or less embryonic connections. You should be able to find this information from the OS vendor but if we can help anymore, please let us know.

Scott

Review Cisco Networking for a $25 gift card