From owner-freebsd-security@freebsd.org Tue Feb 6 05:23:05 2018 Return-Path: Delivered-To: freebsd-security@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id E7BA6EF561F; Tue, 6 Feb 2018 05:23:04 +0000 (UTC) (envelope-from brahma.gdb@gmail.com) Received: from mail-io0-x22f.google.com (mail-io0-x22f.google.com [IPv6:2607:f8b0:4001:c06::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 58F3C762AB; Tue, 6 Feb 2018 05:23:04 +0000 (UTC) (envelope-from brahma.gdb@gmail.com) Received: by mail-io0-x22f.google.com with SMTP id b198so1159156iof.6; Mon, 05 Feb 2018 21:23:04 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to; bh=xO8AVDy/xuGZzGy/Rp61D2rnVaY8QrOCb+cOgSL0fYg=; b=XWYmRC7GEy3CgdrVbJl5BYUQhdNREOolbYC493f3a+EU4txhcspVIQjlI8eA7xK36M TF5P2FwPoqrPXXeQYBY+i5rYUmFsRAa47AJwPbsx9jIVIexTAsjTbv2usFS1bsUiFTbL f56k/YTrMb9odoiOjA8VUKMCERwAjiMCcU82LAJMJgNdebCvmsQ25rfZ/dNl5P2QiJo4 nRO1m2IZ/JwmUF0asWJyqh7UMB6fR+TjszWpfxs7ihtYBSG+Fvw8IT3EjXBYgO5WUQJ8 NzLDJtn3VLvN69/LlGaIguKr/k0z40NyrrG83X+6gpzdakdd6tQojMOA1Rad4ZHVR/+3 /6uQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to; bh=xO8AVDy/xuGZzGy/Rp61D2rnVaY8QrOCb+cOgSL0fYg=; b=pH6X+8XHJ1cKz0FAXubB6bADi8YFAwoqzrXDmUbSUVbkDZeSoWTRtJkVkcYTV8jP0r eCVUEpz5/CKh2IfRdrt2yEB4U1xU8jjVouX1LC5jFmW/EZjp25nYP5UZRGuRX1rcaZge RC5jbr5vWfZ2hksekyfAmmEuVq7aOb8TAhuR9mE6j9UWlmQ8S6TOOjGSUjulayXhniZN 3BXOF8skDtB7qZ4XefKPd4R6BhesTgQbysgcXgQI7WxNAKfgaxsCGMnerA57EtO9/TbR /pHHlI+3A9C8jV7sJy5BuQiuB5pRtq/sWswl3Gu5Jo5KFdpFLViIH5JfjN1ZUxKpqFm5 vmYg== X-Gm-Message-State: APf1xPBoguYOx7a7D5H/WaanRYnxW2GFXTvJrtZ/7CMaRaB6mxQdYATD /L2t8+3y/0BuUYVvLhQqO5jqWB12+75bxd9nSkM= X-Google-Smtp-Source: AH8x225CNH0rkQaN7ilNEG9dTQ/nIKnfVFHnM0Wf/tM9UUh6UcCaaxA+pCgJ2wDvjY2bXiEmbd6s4kIygpvx+nVMyw0= X-Received: by 10.107.7.41 with SMTP id 41mr1477148ioh.249.1517894583505; Mon, 05 Feb 2018 21:23:03 -0800 (PST) MIME-Version: 1.0 Received: by 10.79.227.196 with HTTP; Mon, 5 Feb 2018 21:23:03 -0800 (PST) In-Reply-To: References: From: Brahmanand Reddy Date: Tue, 6 Feb 2018 10:53:03 +0530 Message-ID: Subject: Re: 'Syncookies' feature effects to generate new ISN/random with RST happens 15 seconds delay. To: FreeBSD-security@freebsd.org, freebsd-security-owner@freebsd.org X-Mailman-Approved-At: Tue, 06 Feb 2018 11:42:43 +0000 Content-Type: text/plain; charset="UTF-8" X-Content-Filtered-By: Mailman/MimeDel 2.1.25 X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.25 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 06 Feb 2018 05:23:05 -0000 Dear Experts, Kindly respond about below query and let me know any info required. Thanks and regards, Brahma On Sat, Feb 3, 2018 at 7:17 PM, Brahmanand Reddy wrote: > Dear Experts, > > Recently i observed in 11.0 FreeBsd Kernel. new ISN random generating > every 15 seconds. RST not happens quickly. > > if disable net.inet.tcp.syncookies=0 on syscntrl.conf .. RST happens > quickly and generate new ISN numnber for next SYN requests. > > https://github.com/freebsd/freebsd/blob/master/sys/ > netinet/tcp_syncache.c#L1882 > > Could you please confirm its expected behavior about delay. have notified > this issue, we have any patch please share. > > Thanks in Advance, > Brahma >