TCP: C2S Ambiguity Mismatching SACK Opt in SYN Retrans

This protocol anomaly triggers when it detects a TCP SYN retransmission where the SACK option differs from the one specified with the original SYN. Because it is unknown if the server received the first SYN, IDP cannot determine if SACK is permitted.

Short Name
TCP:C2S:AMBIG:SYN-RTNS--BADSACK
Severity
Info
Recommended
False
Recommended Action
Drop Packet
Category
TCP
Release Date
08/27/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?