Lot of SYN flooding requests on Compute Engine Instances

114 views
Skip to first unread message

Nuthan Kumar

unread,
Jun 24, 2017, 10:01:54 PM6/24/17
to gce-discussion
Hi, 

At times, there's SYN flooding on port 80 on the instances which have public IPs, leading to Kernel panic. This brings the server down due to insufficient CPU/Memory.

kernel: possible SYN flooding on port 80. Sending cookies.

Ideally, How do we get over this problem?

Thanks,
Nuthan.

Irina (Google Cloud Support)

unread,
Jun 26, 2017, 12:49:14 PM6/26/17
to gce-discussion
You can enable SYN flood protection ‘net.ipv4.tcp_syncookies = 1’ by editing the kernel security settings file ‘/etc/sysctl.conf’ as outlined at this article. Also, you can use Google load balancing in your infrastructure that mitigates and absorbs many attacks including SYN floods. Another item that might be interested to you is the best practices for DDoS protection and mitigation on Google Cloud Platform.
Reply all
Reply to author
Forward
0 new messages