{"id":501,"date":"2018-06-30T11:40:41","date_gmt":"2018-06-30T04:40:41","guid":{"rendered":"https:\/\/lagonet.vn\/?p=501"},"modified":"2018-06-30T11:40:41","modified_gmt":"2018-06-30T04:40:41","slug":"cau-hinh-tcp-intercept-watch-mode-phong-chong-tan-cong-dos","status":"publish","type":"post","link":"https:\/\/kb.lagonet.vn\/?p=501","title":{"rendered":"C\u1ea4U H\u00ccNH TCP INTERCEPT WATCH MODE PH\u00d2NG CH\u1ed0NG T\u1ea4N C\u00d4NG DOS"},"content":{"rendered":"<p><b>M\u1ee5c ti\u00eau<\/b>: C\u1ea5u h\u00ecnh \u0111\u1ec3 router gi\u00e1m s\u00e1t c\u00e1c k\u1ebft n\u1ed1i TCP ph\u00f2ng ch\u1ed1ng t\u1ea5n c\u00f4ng DOS<br \/>\n<b>M\u00f4 h\u00ecnh<\/b>:<\/p>\n<div align=\"center\">\n<div align=\"center\"><img decoding=\"async\" class=\"bbcode-attachment\" src=\"http:\/\/img194.imageshack.us\/img194\/5223\/image003rt.gif\" alt=\"\" border=\"0\" \/><\/div>\n<\/div>\n<p><b>M\u00f4 t\u1ea3<\/b>:<br \/>\n&#8211; C\u1ea5u h\u00ecnh NAT t\u0129nh<br \/>\n&#8211; T\u1ea1o ACL 199 v\u00e0 match c\u00e1c k\u1ebft n\u1ed1i TCP port 80 v\u00e0o server.<br \/>\n&#8211; C\u1ea5u h\u00ecnh TCP intercept s\u1eed d\u1ee5ng ACL 199 v\u00e0 d\u00f9ng mode random-drop<br \/>\n&#8211; Router s\u1ebd reset c\u00e1c k\u1ebft n\u1ed1i n\u1ebfu ch\u00fang \u1edf trong t\u00ecnh tr\u1ea1ng half-open h\u01a1n 15 gi\u00e2y.<br \/>\n&#8211; B\u1eaft \u0111\u1ea7u resetting half-open sessions khi s\u1ed1 session l\u00ean \u0111\u1ebfn 1500<br \/>\n&#8211; D\u1eebng resetting half-open sessions khi s\u1ed1 session gi\u1ea3m d\u1ea7n xu\u1ed1ng c\u00f2n 1200<\/p>\n<p><b>C\u1ea5u h\u00ecnh tham kh\u1ea3o<\/b><br \/>\n<b>B\u01b0\u1edbc 1<\/b>: \u0110\u1eb7t \u0111\u1ecba ch\u1ec9 IP, \u0111\u1ecbnh tuy\u1ebfn, c\u1ea5u h\u00ecnh NAT t\u0129nh<br \/>\n<i>Router 4<\/i><br \/>\n!<br \/>\n!<br \/>\ninterface Loopback0<br \/>\nip address 150.1.4.4 255.255.255.0<br \/>\n!<br \/>\ninterface FastEthernet0\/0<br \/>\nip address 155.1.45.4 255.255.255.0<br \/>\nip nat outside<br \/>\nip virtual-reassembly<br \/>\nduplex auto<br \/>\nspeed auto<br \/>\n!<br \/>\ninterface FastEthernet0\/1<br \/>\nip address 10.0.0.4 255.255.255.0<br \/>\nip nat inside<br \/>\nip virtual-reassembly<br \/>\nduplex auto<br \/>\nspeed auto<br \/>\n!<br \/>\ninterface Serial0\/2\/0<br \/>\nno ip address<br \/>\nshutdown<br \/>\nno fair-queue<br \/>\nclockrate 2000000<br \/>\n!<br \/>\nrouter ospf 1<br \/>\nlog-adjacency-changes<br \/>\nnetwork 150.1.4.0 0.0.0.255 area 0<br \/>\nnetwork 155.1.45.0 0.0.0.255 area 0<br \/>\n!<br \/>\nip classless<br \/>\n!<br \/>\n!<br \/>\nip http server<br \/>\nno ip http secure-server<br \/>\nip nat inside source static 10.0.0.1 150.1.4.4<br \/>\n!<br \/>\n!<\/p>\n<p><i>Router1<\/i><br \/>\n!<br \/>\ninterface FastEthernet0\/0<br \/>\nip address 10.0.0.1 255.255.255.0<br \/>\nduplex auto<br \/>\nspeed auto<br \/>\n!<br \/>\nip classless<br \/>\nip route 0.0.0.0 0.0.0.0 10.0.0.4<br \/>\n!<br \/>\n!<\/p>\n<p><i>Router5<\/i><br \/>\n!<br \/>\n!<br \/>\n!<br \/>\n!<br \/>\ninterface FastEthernet0\/0<br \/>\nip address 155.1.45.5 255.255.255.0<br \/>\nduplex auto<br \/>\nspeed auto<br \/>\n!<br \/>\ninterface FastEthernet0\/1<br \/>\nip address 150.1.5.5 255.255.255.0<br \/>\nduplex auto<br \/>\nspeed auto<br \/>\nno keepalive<br \/>\n!<br \/>\n!<br \/>\nrouter ospf 1<br \/>\nlog-adjacency-changes<br \/>\nnetwork 150.1.5.0 0.0.0.255 area 0<br \/>\nnetwork 155.1.45.0 0.0.0.255 area 0<br \/>\n!<br \/>\nip classless<br \/>\nno ip http server<br \/>\n!<br \/>\n!<br \/>\n!<\/p>\n<p><b>B\u01b0\u1edbc 2<\/b>: C\u1ea5u h\u00ecnh TCP intercept \u1edf watch mode<br \/>\n<i>Router 4<\/i><\/p>\n<p>!<br \/>\nip tcp intercept list 199<br \/>\nip tcp intercept mode watch<br \/>\nip tcp intercept watch-timeout 15<br \/>\nip tcp intercept max-incomplete high 1500<br \/>\nip tcp intercept max-incomplete low 1200<br \/>\nip tcp intercept connection-timeout 3600<br \/>\nip tcp intercept drop-mode random<br \/>\n!<br \/>\n!<br \/>\naccess-list 199 permit tcp any any eq 80<br \/>\n!<br \/>\n!<\/p>\n<p><b>B\u01b0\u1edbc 3<\/b>: Ki\u1ec3m tra.<br \/>\nR4#<b>debug ip tcp intercept<\/b><br \/>\nTCP intercept debugging is on<\/p>\n<p>R5#telnet 150.1.4.4 80<br \/>\nTrying 150.1.4.4, 80 &#8230; Open<\/p>\n<p>[Connection to 150.1.4.4 closed by foreign host]<\/p>\n<p>R4#<br \/>\nMar 8 10:10:58.783: INTERCEPT: new connection (155.1.45.5:53353 SYN -&gt; 10.0.0.1:80)<br \/>\nMar 8 10:10:59.099: INTERCEPT: client packet passed in SYNSENT (155.1.45.5:53353 -&gt; 10.0.0.1:80)<br \/>\nMar 8 10:10:59.103: INTERCEPT: client packet passed in SYNSENT (155.1.45.5:53353 -&gt; 10.0.0.1:80)<br \/>\nMar 8 10:11:13.787: INTERCEPT: SYNSENT timing out (155.1.45.5:53353 &lt;-&gt; 10.0.0.1:80)<br \/>\nMar 8 10:11:13.791: INTERCEPT(*): (155.1.45.5:53353 RST -&gt; 10.0.0.1:80) =&gt; (1)<br \/>\nR4#<\/p>\n<p>(1) K\u1ebft n\u1ed1i \u0111\u00e3 qu\u00e1 th\u1eddi gian timeout, router s\u1ebd g\u1eedi c\u1edd RST t\u1edbi server.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>M\u1ee5c ti\u00eau: C\u1ea5u h\u00ecnh \u0111\u1ec3 router gi\u00e1m s\u00e1t c\u00e1c k\u1ebft n\u1ed1i TCP ph\u00f2ng ch\u1ed1ng t\u1ea5n c\u00f4ng DOS M\u00f4 h\u00ecnh: M\u00f4 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[25,19,6],"tags":[],"class_list":["post-501","post","type-post","status-publish","format-standard","hentry","category-cisco","category-issues","category-networking"],"_links":{"self":[{"href":"https:\/\/kb.lagonet.vn\/index.php?rest_route=\/wp\/v2\/posts\/501","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kb.lagonet.vn\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kb.lagonet.vn\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kb.lagonet.vn\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kb.lagonet.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=501"}],"version-history":[{"count":0,"href":"https:\/\/kb.lagonet.vn\/index.php?rest_route=\/wp\/v2\/posts\/501\/revisions"}],"wp:attachment":[{"href":"https:\/\/kb.lagonet.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=501"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kb.lagonet.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=501"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kb.lagonet.vn\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=501"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}