TCP: S2C Ambiguity Mismatching Seq Num in FIN Retrans

This protocol anomaly triggers when it detects a TCP FIN retransmission in which the retransmitted SEQUENCE number does not match the SEQUENCE number of the original FIN. Because it is unknown if the server has received the first FIN, IDP cannot determine when the flow ends.

Short Name
TCP:AUDIT:S2C-FINRETR-BADSEQ
Severity
Info
Recommended
False
Recommended Action
None
Category
TCP
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?