HP 6125XLG R2306-HP 6125XLG Blade Switch Layer 3 - IP Services Configuration G - Page 119

Configuring TCP timers, Enabling sending ICMP error packets

Page 119 highlights

Configuring TCP timers You can configure the following TCP timers: • SYN wait timer-TCP starts the SYN wait timer after sending a SYN packet. If no response packet is received within the SYN wait timer interval, TCP fails to establish the connection. • FIN wait timer-TCP starts the FIN wait timer when the state changes to FIN_WAIT_2. If no FIN packet is received within the timer interval, TCP terminates the connection. If a FIN packet is received, TCP changes connection state to TIME_WAIT. If a non-FIN packet is received, TCP restarts the timer, and tears down the connection when the timer expires. To configure TCP timers: Step 1. Enter system view. Command system-view 2. Configure TCP timers. • Configure the TCP SYN wait timer: tcp timer syn-timeout time-value • Configure the TCP FIN wait timer: tcp timer fin-timeout time-value Remarks N/A By default: • The TCP SYN wait timer is 75 seconds. • The TCP FIN wait timer is 675 seconds. Enabling sending ICMP error packets Perform this task to enable sending ICMP error packets, including redirect, time-exceeded, and destination unreachable packets. • ICMP redirect packets A host that has only one default route sends all packets to the default gateway. The default gateway sends an ICMP redirect packet to inform the host of a correct next hop by following these rules: { The receiving and sending interfaces are the same. { The selected route is not created or modified by any ICMP redirect packet. { The selected route is not destined for 0.0.0.0. { There is no source route option in the received packet. ICMP redirect packets simplify host management and enable hosts to gradually optimize their routing table. • ICMP time-exceeded packets A device sends ICMP time-exceeded packets by following these rules: { If a received packet is not destined for the device and the TTL field of the packet is 1, the device sends an ICMP TTL Expired in Transit packet to the source. { When the device receives the first fragment of an IP datagram destined for it, it starts a timer. If the timer expires before all the fragments of the datagram are received, the device sends an ICMP Fragment Reassembly Timeout packet to the source. • ICMP destination unreachable packets A device sends ICMP destination unreachable packets by following these rules: 111

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230

111
Configuring TCP timers
You can configure the following TCP timers:
SYN wait timer
—TCP starts the SYN wait timer after sending a SYN packet. If no response packet
is received within the SYN wait timer interval, TCP fails to establish the connection.
FIN wait timer
—TCP starts the FIN wait timer when the state changes to FIN_WAIT_2. If no FIN
packet is received within the timer interval, TCP terminates the connection. If a FIN packet is
received, TCP changes connection state to TIME_WAIT. If a non-FIN packet is received, TCP restarts
the timer, and tears down the connection when the timer expires.
To configure TCP timers:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Configure TCP timers.
Configure the TCP SYN wait timer:
tcp timer syn-timeout
time-value
Configure the TCP FIN wait timer:
tcp timer fin-timeout
time-value
By default:
The TCP SYN wait timer is 75
seconds.
The TCP FIN wait timer is 675
seconds.
Enabling sending ICMP error packets
Perform this task to enable sending ICMP error packets, including redirect, time-exceeded, and
destination unreachable packets.
ICMP redirect packets
A host that has only one default route sends all packets to the default gateway. The default
gateway sends an ICMP redirect packet to inform the host of a correct next hop by following these
rules:
{
The receiving and sending interfaces are the same.
{
The selected route is not created or modified by any ICMP redirect packet.
{
The selected route is not destined for 0.0.0.0.
{
There is no source route option in the received packet.
ICMP redirect packets simplify host management and enable hosts to gradually optimize their
routing table.
ICMP time-exceeded packets
A device sends ICMP time-exceeded packets by following these rules:
{
If a received packet is not destined for the device and the TTL field of the packet is 1, the device
sends an ICMP TTL Expired in Transit packet to the source.
{
When the device receives the first fragment of an IP datagram destined for it, it starts a timer. If
the timer expires before all the fragments of the datagram are received, the device sends an
ICMP Fragment Reassembly Timeout packet to the source.
ICMP destination unreachable packets
A device sends ICMP destination unreachable packets by following these rules: