[Contents] [Prev] [Next] [Index] [Report an Error]


ASP_IDS_TCP_SYN_ATTACK

System Log Message

ASP_IDS_TCP_SYN_ATTACK:
proto protocol-number (protocol-name), source-interface-name:source-address:source-port -> destination-address:destination-port, TCP SYN flood attack

Description

The stateful firewall received the packet with the indicated characteristics and determined that it was a duplicate Transmission Control Protocol (TCP) SYN packet (the SYN flag was set and a SYN packet was already received for the flow to the destination). The event was reported to intrusion detection services (IDS) and can cause IDS to activate SYN cookie protection. The packet contained the indicated information about its protocol (numerical identifier and name), source (logical interface name, IP address, and port number), and destination (IP address and port number).

Type

Event: This message reports an event, not an error

Severity

error


[Contents] [Prev] [Next] [Index] [Report an Error]