
Parameters
client_ip
2.47.43. disallow_clientkeyexchange (ID: 03700501)
Default Severity
ERROR
Log Message
SSL Handshake: Disallow ClientKeyExchange. Closing down SSL
connection
Explanation
The SSL connection will be closed because there are not enough
resources to process any ClientKeyExchange messages at the moment.
This could be a result of SSL handshake message flooding. This action
is triggered by a system that monitors the amount of resources that is
spent on key exchanges. This system is controlled by the advanced
setting SSL_ProcessingPriority.
Gateway Action
ssl_close
Recommended Action
Investigate the source of this, and try to find out if it is a part of a
possible attack, or normal traffic.
Revision
2
Parameters
client_ip
2.47.44. bad_packet_order (ID: 03700502)
Default Severity
ERROR
Log Message
Bad SSL Handshake packet order. Closing down SSL connection
Explanation
Two or more SSL Handshake message were received in the wrong
order, and the SSL connection is closed.
Gateway Action
ssl_close
Recommended Action
None.
Revision
1
Parameters
client_ip
2.47.45. bad_clienthello_msg (ID: 03700503)
Default Severity
ERROR
Log Message
SSL Handshake: Bad ClientHello message. Closing down SSL
connection
Explanation
The ClientHello message (which is the first part of a SSL handshake)
is invalid, and the SSL connection is closed.
Gateway Action
ssl_close
Recommended Action
None.
Revision
1
2.47.43. disallow_clientkeyexchange
(ID: 03700501)
Chapter 2. Log Message Reference
464
Содержание DFL- 860
Страница 25: ...List of Tables 1 Abbreviations 28 25 ...
Страница 26: ...List of Examples 1 Log Message Parameters 27 2 Conditional Log Message Parameters 27 26 ...
Страница 36: ...1 3 Severity levels Chapter 1 Introduction 36 ...
Страница 156: ...Recommended Action None Revision 1 2 5 7 unsynced_databases ID 05000008 Chapter 2 Log Message Reference 156 ...
Страница 173: ...Context Parameters Packet Buffer 2 9 14 route_collision ID 00700015 Chapter 2 Log Message Reference 173 ...
Страница 195: ...2 12 6 route_removed ID 01100006 Chapter 2 Log Message Reference 195 ...
Страница 240: ...Revision 1 Parameters iface linkspeed duplex 2 20 3 ifacemon_status_bad ID 03900004 Chapter 2 Log Message Reference 240 ...
Страница 309: ...Context Parameters Rule Name Packet Buffer 2 24 3 ip_rsv_flag_set ID 01600003 Chapter 2 Log Message Reference 309 ...
Страница 409: ...2 40 19 scp_failed_not_admin ID 04704000 Chapter 2 Log Message Reference 409 ...
Страница 476: ...2 49 14 zd_block ID 03800014 Chapter 2 Log Message Reference 476 ...