I am getting a lot of 1204/0 and 1208/0 hits for a particular server behind FWSM with destination traffic being 18.104.22.168 and protocol being UDP.
These signatures are relating to Missing Initial fragment and IP Fragment Incomplete datagram.
Do you have any suggestions on how to handle this?
The sensor is operating in both promiscous as well as inline mode but i dont remember exactly if this event is coming from the virtual sensor in promiscous mode or inline mode. I believe it is promiscous.
Any ideas would really be appreciated.
Thanks and Regards