L4 RST-SYN

TCP RST-SYN flood

RST and SYN together (RS preset) — contradictory signals that confuse session tracking and teardown logic.

How it works

  1. Engarde preset: RST-SYN Flood — flag RS, invalid_flag true.
  2. Useful for testing state cleanup when contradictory flags arrive at high PPS.
  3. Related presets: RSF (RST-SYN-FIN), ARS (ACK-RST-SYN).

Packet flow (illustrative)

Segments with RST + SYN flags (RS).

Illustrative flow — not a live capture.

Flag RS
Engarde RST-SYN Flood
Layer L4 state

What to watch in Engarde

  • Session table churn rate.
  • Legitimate SYN drops during RS flood if state is polluted.

Running this simulation

RS preset on firewall lab; compare recovery time after End test with SYN-only baseline.

Mitigation perspective

Stateful devices should drop RS combos early; verify with Engarde report timestamps.