ASP_IDS_TCP_SYN_ATTACK
System Log Message
ASP_IDS_TCP_SYN_ATTACK:
proto protocol-number (protocol-name), source-interface-name:source-address:source-port -> destination-address:destination-port, TCP SYN flood attackDescription
The stateful firewall received the packet with the indicated characteristics and determined that it was a duplicate Transmission Control Protocol (TCP) SYN packet (the SYN flag was set and a SYN packet was already received for the flow to the destination). The event was reported to intrusion detection services (IDS) and can cause IDS to activate SYN cookie protection. The packet contained the indicated information about its protocol (numerical identifier and name), source (logical interface name, IP address, and port number), and destination (IP address and port number).
Type
Event: This message reports an event, not an error
Severity