06-02-2008 05:39 PM - edited 03-10-2019 04:08 AM
i have a IPS 4260 monitoring 4 inline links, connecting to a MARS 20.
MARS having been reporting a large amount of TCP related alerts over WAN; ie:
-TCP packet with segment out of order,
-TCP packet out of state order,
-TCP segment out of window,
-TCP Packet With Bad Checksum
Can anyone advice on the best practise or how should i assess and handle these situation?
Thanks
cash
06-03-2008 01:25 PM
Even if you decide to continue to alert on this sigantures, I would recommend creating a drop rule with "log to db only" for these alarms. They occur too often in "normal" traffic for them to be useful.
06-22-2008 05:20 PM
Sounds like a problem with the ISP. They may have a congested backbone or a faulty piece of equipment causing the errors. I would check the configuration of the links and interface errors.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide