Connectivity issues under a SYN flood

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Yossi Attas [MSFT] (yossia_at_online.microsoft.com)
Date: 09/05/04


Date: Sun, 5 Sep 2004 16:11:22 +0300

We have recently learnt that when installed on a machine with certain
network adapters, ISA 2004 may have connectivity issues while being under a
flood of SYN packets.

The issue is related to the TCP/IP stack's ability to allow the network
adapter to calculate the TCP checksum by itself in certain scenarios.
This feature is also known as Task Offloading.
Apparently, while being in SYN attack protection mode, ISA does not utilize
the task offloading feature properly which results in corrupt checksums and
therefore failure to create new TCP connections.

The workaround for this issue is to disable Task Offloading.
To do so in registry location
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters,
create a DWORD value called DisableTaskOffload, and set it to 1.

This option requires restart of the machine.
A KB is to be published soon.

Thanks,
Yossi Attas [MSFT]



Relevant Pages

  • Connectivity issues while being under a flood of SYN packets
    ... network adapters, ISA 2004 may have connectivity issues while being under a ... Apparently, while being in SYN attack protection mode, ISA does not utilize ...
    (microsoft.public.isa)
  • Re: Connectivity issues under a SYN flood
    ... Finally resolved the problem of connectivity instability ?! ... > network adapters, ISA 2004 may have connectivity issues while being under ... > This feature is also known as Task Offloading. ...
    (microsoft.public.isaserver)
  • RE: VPN Connects, but no Internal IP or network resources.
    ... versions of ISA yet seem to be having the same trouble. ... I just noticed in this post though, that you can't even ping the other ... an access issue rather than connectivity. ... My ISA server is going to be down until I rebuild it, so I can't even do any ...
    (microsoft.public.isa.vpn)
  • Re: No connection to Active Directory
    ... I have noticed this alert in the connectivity monitoring: ... the configuration of the ISA 2004 returning the following alert: ... the ISA server machine.Any ideas? ...
    (microsoft.public.isa)
  • network connect just up and died
    ... I was computing happily via my VPN when all of a sudden, ... When I inspected the Device Manager, I found that one of the drivers ... drivers installed under 'Network Adapters": ... have no connectivity (note: ...
    (microsoft.public.windowsxp.network_web)