diff options
author | Hannes Frederic Sowa <hannes@stressinduktion.org> | 2013-07-26 11:43:23 -0400 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2013-07-30 19:15:18 -0400 |
commit | 5ad37d5deee1ff7150a2d0602370101de158ad86 (patch) | |
tree | 602cac8fe98e0911753b7ff0485756962c2d232a /net/ipv6 | |
parent | dcfd8d5830f8cc9062eb7040f455c034e8d160e6 (diff) |
tcp: add tcp_syncookies mode to allow unconditionally generation of syncookies
| If you want to test which effects syncookies have to your
| network connections you can set this knob to 2 to enable
| unconditionally generation of syncookies.
Original idea and first implementation by Eric Dumazet.
Cc: Florian Westphal <fw@strlen.de>
Cc: David Miller <davem@davemloft.net>
Signed-off-by: Eric Dumazet <eric.dumazet@gmail.com>
Signed-off-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/ipv6')
-rw-r--r-- | net/ipv6/tcp_ipv6.c | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/net/ipv6/tcp_ipv6.c b/net/ipv6/tcp_ipv6.c index b792e870686b..38c196ca6011 100644 --- a/net/ipv6/tcp_ipv6.c +++ b/net/ipv6/tcp_ipv6.c | |||
@@ -963,7 +963,8 @@ static int tcp_v6_conn_request(struct sock *sk, struct sk_buff *skb) | |||
963 | if (!ipv6_unicast_destination(skb)) | 963 | if (!ipv6_unicast_destination(skb)) |
964 | goto drop; | 964 | goto drop; |
965 | 965 | ||
966 | if (inet_csk_reqsk_queue_is_full(sk) && !isn) { | 966 | if ((sysctl_tcp_syncookies == 2 || |
967 | inet_csk_reqsk_queue_is_full(sk)) && !isn) { | ||
967 | want_cookie = tcp_syn_flood_action(sk, skb, "TCPv6"); | 968 | want_cookie = tcp_syn_flood_action(sk, skb, "TCPv6"); |
968 | if (!want_cookie) | 969 | if (!want_cookie) |
969 | goto drop; | 970 | goto drop; |