Table C-18. System Logs: Invalid Packets (continued)
Message
Explanation
Recommended Action
Message
Explanation
Recommended Action
Message
Explanation
Recommended Action
Message
Explanation
Recommended Action
Message
System Logs and Error Messages
ProSafe VPN Firewall 200 FVX538 Reference Manual
2007 Oct 1 00:44:17 [FVX538] [kernel]
[INVALID][RST_PACKET][DROP] SRC=192.168.20.10
DST=192.168.20.2 PROTO=TCP SPT=23 DPT=54899
Invalid RST packet
1. Invalid packets are dropped.
2. Use this command to enable dropping and logging of the invalid packets:
fw/rules/attackChecks/configure dropInvalid 1
To allow invalid packet and disable logging:
fw/rules/attackChecks/configure dropInvalid 0
2007 Oct 1 00:44:17 [FVX538] [kernel]
[INVALID][ICMP_TYPE][DROP] SRC=192.168.20.10
DST=192.168.20.2 PROTO=ICMP TYPE=19 CODE=0
Invalid ICMP Type
1. Invalid packets are dropped.
2. Use this command to enable dropping and logging of the invalid packets:
fw/rules/attackChecks/configure dropInvalid 1
To allow invalid packet and disable logging:
fw/rules/attackChecks/configure dropInvalid 0
2007 Oct 1 00:44:17 [FVX538] [kernel]
[INVALID][TCP_FLAG_COMBINATION][DROP] SRC=192.168.20.10
DST=192.168.20.2 PROTO=TCP SPT=23 DPT=54899
Invalid TCP flag combination
1. Invalid packets are dropped.
2. Use this command to enable dropping and logging of the invalid packets:
fw/rules/attackChecks/configure dropInvalid 1
To allow invalid packet and disable logging:
fw/rules/attackChecks/configure dropInvalid 0
2007 Oct 1 00:44:17 [FVX538] [kernel]
[INVALID][BAD_CHECKSUM]DROP] SRC=192.168.20.10
DST=192.168.20.2 PROTO=TCP SPT=23 DPT=54899
Bad Checksum
1. Invalid packets are dropped.
2. Use this command to enable dropping and logging of the invalid packets:
fw/rules/attackChecks/configure dropInvalid 1
To allow invalid packet and disable logging:
fw/rules/attackChecks/configure dropInvalid 0
2007 Oct 1 00:44:17 [FVX538] [kernel]
[INVALID][BAD_HW_CHECKSUM][DROP] SRC=192.168.20.10
DST=192.168.20.2 PROTO=ICMP TYPE=3 CODE=0
v1.0, January 2010
C-11