2.42.4. tcp_flag_set (ID: 03300004)
Gateway Action
Recommended Action
Revision
Parameters
Context Parameters
2.42.4. tcp_flag_set (ID: 03300004)
Default Severity
Log Message
Explanation
Gateway Action
Recommended Action
Revision
Parameters
Context Parameters
2.42.5. tcp_null_flags (ID: 03300005)
Default Severity
Log Message
Explanation
Gateway Action
Recommended Action
Revision
Context Parameters
2.42.6. tcp_flags_set (ID: 03300008)
Default Severity
Log Message
Explanation
Gateway Action
ignore
None.
1
bad_flag
Rule Name
Packet Buffer
NOTICE
The TCP <bad_flag> flag is set. Stripping
A "bad" TCP flag is set. Removing it.
strip_flag
None.
1
bad_flag
Rule Name
Packet Buffer
NOTICE
Packet has no SYN, ACK, FIN or RST flag set
The packet has no SYN, ACK, FIN or RST flag set. Ignoring.
ignore
None.
1
Rule Name
Packet Buffer
WARNING
The TCP <good_flag> and <bad_flag> flags are set. Dropping
The possible combinations for these flags are: SYN URG, SYN PSH,
SYN RST, SYN FIN and FIN URG.
drop
425
Chapter 2. Log Message Reference