Juniper JUNOS OS 10.3 - SYSTEM LOG MESSAGES REFERENCE 7-12-2010 Reference Manual page 146

System log messages reference
Table of Contents

Advertisement

Junos 10.3 System Log Messages Reference
Description
Type
Severity
Facility
ASP_IDS_SYN_COOKIE_ON
System Log Message
Description
Type
Severity
Facility
ASP_IDS_TCP_SYN_ATTACK
System Log Message
Description
Type
Severity
Facility
82
Intrusion detection services (IDS) deactivated SYN cookie protection for the indicated
destination address. IDS deactivates this protection when it learns from the stateful
firewall that the rate of certain events has returned to a level below the threshold set by
the 'threshold' statement at the [edit services ids rule <rule-name> term <term-name>
then syn-cookie] hierarchy level. The relevant events include the ones reported by the
ASP_IDS_TCP_SYN_ATTACK, ASP_SFW_SYN_DEFENSE, and ASP_SFW_TCP_SCAN
system log messages.
Event: This message reports an event, not an error
error
LOG_PFE
Host destination-address, SYN-COOKIE protection activated
Intrusion detection services (IDS) activated SYN cookie protection for the indicated
destination address, because it learned from the stateful firewall that the rate of certain
events exceeded the threshold set by the 'threshold' statement at the [edit services ids
rule <rule-name> term <term-name> then syn-cookie] hierarchy level. The events include
the ones reported by the ASP_IDS_TCP_SYN_ATTACK, ASP_SFW_SYN_DEFENSE, and
ASP_SFW_TCP_SCAN system log messages. When SYN cookie protection is activated
for a flow to a destination and the TCP handshake has not completed, the stateful firewall
generates a SYN/ACK packet for each SYN packet directed to the destination.
Event: This message reports an event, not an error
error
LOG_PFE
syslog-prefix error-code: proto protocol-id (protocol-name),
source-interface-nameseparatorsource-address:source-port ->
destination-addressdestination-port, event-type
The stateful firewall received the packet with the indicated characteristics and determined
that it was a duplicate Transmission Control Protocol (TCP) SYN packet (the SYN flag
was set and a SYN packet was already received for the flow to the destination). The
event was reported to intrusion detection services (IDS) and can cause IDS to activate
SYN cookie protection. The packet contained the indicated information about its protocol
(numerical identifier and name), source (logical interface name, IP address, and port
number), and destination (IP address and port number).
Event: This message reports an event, not an error
error
LOG_PFE
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the JUNOS OS 10.3 - SYSTEM LOG MESSAGES REFERENCE 7-12-2010 and is the answer not in the manual?

Questions and answers

This manual is also suitable for:

Junos os 10.3 - software

Table of Contents

Save PDF