TMG為防止大量SYN(SynAttackHalfOpen)行為造成主機效能低落,所以在SYN達到上限值(預設值1000)時,會啟動保護機制,拒絕新連線行為,低於下限值(預設值200),則再重新接受新連線
可透過修改登錄值,來放大預設值
以下範例放大到2000-1500
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\FwEng\Parameters]
"SynAttackHalfOpenEnable"=dword:000007d0
"SynAttackHalfOpenDisable"=dword:000005dc
http://social.technet.microsoft.com/Forums/forefront/en-US/db60398b-c8f2-4d25-8f85-94ffb5aaeb7e/forefront-tmg-2010-lockdown-no-traffic-fromto-lan-or-wan
可透過修改登錄值,來放大預設值
以下範例放大到2000-1500
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\FwEng\Parameters]
"SynAttackHalfOpenEnable"=dword:000007d0
"SynAttackHalfOpenDisable"=dword:000005dc
http://social.technet.microsoft.com/Forums/forefront/en-US/db60398b-c8f2-4d25-8f85-94ffb5aaeb7e/forefront-tmg-2010-lockdown-no-traffic-fromto-lan-or-wan
留言
張貼留言