Disallow_Clientkeyexchange (Id: 03700501); Bad_Packet_Order (Id: 03700502); Bad_Clienthello_Msg (Id: 03700503) - D-Link NetDefend DFL-210 Log Reference Manual

Network security firewall
Hide thumbs Also See for NetDefend DFL-210:
Table of Contents

Advertisement

2.47.43. disallow_clientkeyexchange
(ID: 03700501)
Parameters

2.47.43. disallow_clientkeyexchange (ID: 03700501)

Default Severity
Log Message
Explanation
Gateway Action
Recommended Action
Revision
Parameters

2.47.44. bad_packet_order (ID: 03700502)

Default Severity
Log Message
Explanation
Gateway Action
Recommended Action
Revision
Parameters

2.47.45. bad_clienthello_msg (ID: 03700503)

Default Severity
Log Message
Explanation
Gateway Action
Recommended Action
Revision
client_ip
ERROR
SSL Handshake: Disallow ClientKeyExchange. Closing down SSL
connection
The SSL connection will be closed because there are not enough
resources to process any ClientKeyExchange messages at the moment.
This could be a result of SSL handshake message flooding. This action
is triggered by a system that monitors the amount of resources that is
spent on key exchanges. This system is controlled by the advanced
setting SSL_ProcessingPriority.
ssl_close
Investigate the source of this, and try to find out if it is a part of a
possible attack, or normal traffic.
2
client_ip
ERROR
Bad SSL Handshake packet order. Closing down SSL connection
Two or more SSL Handshake message were received in the wrong
order, and the SSL connection is closed.
ssl_close
None.
1
client_ip
ERROR
SSL Handshake: Bad ClientHello message. Closing down SSL
connection
The ClientHello message (which is the first part of a SSL handshake)
is invalid, and the SSL connection is closed.
ssl_close
None.
1
464
Chapter 2. Log Message Reference

Advertisement

Table of Contents
loading

Table of Contents