Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

FIN sweep to external networks

Please give me some pointers about the following, where to get more info etc. Thanks.

1) All the FIN-sweep-related IDS events that were logged in our system has our ip addr as the destination.

Is it because IDS chooses to monitor fin sweeps targeted at the local network only, or is it because of other technical reasons: not feasible to keep track of the 3-way handshakes or closed/not-open connections, or we need to tune our configuration.

2) what is the default for the AlarmThrottle parm, if it is not set?


Re: FIN sweep to external networks

Since there has been no response to your post, it appears to be either too complex or too rare an issue for other forum members to assist you. If you don't get a suitable response to your post, you may wish to review our resources at the online Technical Assistance Center ( or speak with a TAC engineer. You can open a TAC case online at

If anyone else in the forum has some advice, please reply to this thread.

Thank you for posting.