
2.42. TCP_FLAG
These log messages refer to the TCP_FLAG (Events concerning the TCP header flags) category.
2.42.1. tcp_flags_set (ID: 03300001)
Default Severity
NOTICE
Log Message
The TCP <good_flag> and <bad_flag> flags are set. Allowing
Explanation
The possible combinations for these flags are: SYN URG, SYN PSH,
SYN RST, SYN FIN and FIN URG.
Gateway Action
allow
Recommended Action
If any of these combinations should either be dropped or having the
bad flag stripped, specify this in configuration, in the "Settings" sub
system.
Revision
1
Parameters
good_flag
bad_flag
Context Parameters
Rule Name
Packet Buffer
2.42.2. tcp_flags_set (ID: 03300002)
Default Severity
WARNING
Log Message
The TCP <good_flag> and <bad_flag> flags are set. Stripping
<bad_flag> flag
Explanation
The possible combinations for these flags are: SYN URG, SYN PSH,
SYN RST, SYN FIN and FIN URG. Removing the "bad" flag.
Gateway Action
strip_bad_flag
Recommended Action
If any of these combinations should either be dropped or ignored,
specify this in configuration, in the "Settings" sub system.
Revision
1
Parameters
good_flag
bad_flag
Context Parameters
Rule Name
Packet Buffer
2.42.3. tcp_flag_set (ID: 03300003)
Default Severity
NOTICE
Log Message
The TCP <bad_flag> flag is set. Ignoring
Explanation
The TCP flag is set. Ignoring.
2.42. TCP_FLAG
Chapter 2. Log Message Reference
424
Summary of Contents for DFL-210 - NetDefend - Security Appliance
Page 25: ...List of Tables 1 Abbreviations 28 25...
Page 26: ...List of Examples 1 Log Message Parameters 27 2 Conditional Log Message Parameters 27 26...
Page 36: ...1 3 Severity levels Chapter 1 Introduction 36...
Page 195: ...2 12 6 route_removed ID 01100006 Chapter 2 Log Message Reference 195...
Page 409: ...2 40 19 scp_failed_not_admin ID 04704000 Chapter 2 Log Message Reference 409...
Page 476: ...2 49 14 zd_block ID 03800014 Chapter 2 Log Message Reference 476...