2.42.7. tcp_flag_set (ID: 03300009)
Recommended Action
Revision
Parameters
Context Parameters
2.42.7. tcp_flag_set (ID: 03300009)
Default Severity
Log Message
Explanation
Gateway Action
Recommended Action
Revision
Parameters
Context Parameters
2.42.8. unexpected_tcp_flags (ID: 03300010)
Default Severity
Log Message
Explanation
Gateway Action
Recommended Action
Revision
Parameters
Context Parameters
2.42.9. mismatched_syn_resent (ID: 03300011)
If any of these combinations should either be ignored or having the
bad flag stripped, specify this in configuration, in the "Settings" sub
system.
1
good_flag
bad_flag
Rule Name
Packet Buffer
WARNING
The TCP <bad_flag> flag is set. Dropping
The TCP flag is set. Dropping packet.
drop
None.
1
bad_flag
Rule Name
Packet Buffer
WARNING
Unexpected tcp flags <flags> from <endpoint> during state <state>.
Dropping
Received unexpected tcp flags during a specific state. Dropping
packet.
drop
None.
1
flags
endpoint
state
Rule Name
Connection
Packet Buffer
426
Chapter 2. Log Message Reference