SYN flood protection not working?

Psychosis (psychos@xeo.net)
Tue, 19 Nov 1996 06:17:18 -0700 (MST)


I'm using kernel 2.1.10... I tried syn flooding my telnet port, and it
still froze up, sending it as few as 10 packets/second. It would seem to
me that real syns are being dropped along with fake syns. How does the syn
flood protection work? Are the oldest un-acked syns being dropped? It
doesn't seem like this to me, because most real connections coming in
fail.

I got lots of messages like this:
Nov 19 08:12:39 fusion kernel: droping syn ack:10 max:10
Nov 19 08:12:39 fusion last message repeated 2 times
Nov 19 08:12:39 fusion kernel: droping syn ack:10 max:10
Nov 19 08:12:41 fusion last message repeated 18 times
Nov 19 08:12:41 fusion kernel: syn_ack rtx 1
Nov 19 08:12:41 fusion last message repeated 3 times
Nov 19 08:12:41 fusion kernel: droping syn ack:10 max:10
Nov 19 08:12:42 fusion last message repeated 4 times
Nov 19 08:12:42 fusion kernel: syn_ack rtx 1
Nov 19 08:12:42 fusion kernel: syn_ack rtx 1
Nov 19 08:12:42 fusion kernel: droping syn ack:10 max:10
Nov 19 08:12:46 fusion last message repeated 32 times