// // Copyright (c) 2018 Michael Tuexen // All rights reserved. // // Redistribution and use in source and binary forms, with or without // modification, are permitted provided that the following conditions // are met: // 1. Redistributions of source code must retain the above copyright // notice, this list of conditions and the following disclaimer. // 2. Redistributions in binary form must reproduce the above copyright // notice, this list of conditions and the following disclaimer in the // documentation and/or other materials provided with the distribution. // // THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND // ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE // IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE // ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE // FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL // DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS // OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) // HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT // LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY // OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF // SUCH DAMAGE. // --ip_version=ipv4 0.00 `sysctl -w net.inet.tcp.hostcache.purgenow=1` +0.00 `sysctl -w net.inet.tcp.syncookies_only=0` +0.00 `sysctl -w net.inet.tcp.syncookies=1` +0.00 `sysctl -w net.inet.tcp.rfc1323=1` +0.00 `sysctl -w net.inet.tcp.sack.enable=1` +0.00 `sysctl -w net.inet.tcp.ecn.enable=2` // Enable server side of TCP fast open. +0.00 `sysctl -w net.inet.tcp.fastopen.server_enable=1` +0.00 `sysctl -w net.inet.tcp.fastopen.acceptany=1` // Create a listening TCP socket +0.00 socket(..., SOCK_STREAM, IPPROTO_TCP) = 3 +0.00 setsockopt(3, SOL_SOCKET, SO_REUSEADDR, [1], 4) = 0 +0.00 setsockopt(3, IPPROTO_TCP, TCP_FASTOPEN, [1], 4) = 0 +0.00 bind(3, ..., ...) = 0 +0.00 listen(3, 2) = 0 // Establish the connection +0.10 < S 0:100(100) win 65535 +0.00 accept(3, ..., ...) = 4 +0.00 close(3) = 0 +0.00 recv(4, ..., 1000, 0) = 100 +0.00 send(4, ..., 200, 0) = 200 +0.00 > S. 0:200(200) ack 101 win 65535 +0.00 send(4, ..., 200, 0) = 200 // Initiate the teardown of the connection. +0.00 close(4) = 0 +0.10 < . 101:101(0) ack 201 win 65535 +0.00 > FP. 201:401(200) ack 101 win 65535 +0.10 < F. 101:101(0) ack 402 win 32767 +0.00 > . 402:402(0) ack 102 win 65535 +0.00 `sysctl -w net.inet.tcp.fastopen.acceptany=0`