Home > Configuration > Lsn > setlsntransportprofile_syncheck

setlsntransportprofile_syncheck

Use this method to set silently drop any non-SYN packets for connections for which there is no LSN-NAT session present on the Citrix ADC.

If you disable this parameter, the Citrix ADC accepts any non-SYN packets and creates a new LSN session entry for this connection.

Following are some reasons for the Citrix ADC to receive such packets:

* LSN session for a connection existed but the Citrix ADC removed this session because the LSN session was idle for a time that exceeded the configured session timeout.
* Such packets can be a part of a DoS attack.

Syntax



Parameters

transportprofilename

Name for the LSN transport profile. Must begin with an ASCII alphanumeric or underscore (_) character, and must contain only ASCII alphanumeric, underscore, hash (#), period (.), space, colon (:), at (@), equals (=), and hyphen (-) characters. Cannot be changed after the LSN transport profile is created. The following requirement applies only to the Citrix ADC CLI: If the name includes one or more spaces, enclose the name in double or single quotation marks (for example, "lsn transport profile1" or 'lsn transport profile1').
This is mandatory parameter.

syncheck

Silently drop any non-SYN packets for connections for which there is no LSN-NAT session present on the Citrix ADC. If you disable this parameter, the Citrix ADC accepts any non-SYN packets and creates a new LSN session entry for this connection. Following are some reasons for the Citrix ADC to receive such packets: * LSN session for a connection existed but the Citrix ADC removed this session because the LSN session was idle for a time that exceeded the configured session timeout. * Such packets can be a part of a DoS attack.
Default value = ENABLED.
Possible Values : ENABLED, DISABLED.

Return Value

Returns simpleResult

See Also