TCP: Options Error Unsolicited SACKPERM

This protocol anomaly triggers when it detects a SACKPERM option in a SYN-ACK packet, even though the client did not specify SACKPERM in the SYN packet. Because these ambiguous packets can be interpreted by the receiving TCP stack in different, unpredictable ways, it is recommended to drop them.

Short Name
TCP:AUDIT:UNSOL-SACKPERM
Severity
Info
Recommended
False
Recommended Action
None
Category
TCP
Keywords
SACKPERM SYN-ACK TCP option
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?