2.57. TCP_FLAG
These log messages refer to the TCP_FLAG (Events concerning the TCP header flags)
category.
2.57.1. tcp_flags_set (ID: 03300001)
Default Severity NOTICE
Log Message The TCP <good_flag> and <bad_flag> flags are set. Allowing
Explanation The possible combinations for these flags are: SYN URG, SYN PSH,
SYN RST, SYN FIN and FIN URG.
Gateway Action allow
Recommended Action If any of these combinations should either be dropped or having the
bad flag stripped, specify this in configuration, in the "Settings" sub
system.
Revision 1
Parameters good_flag
bad_flag
Context Parameters Rule Name
Packet Buffer
2.57.2. tcp_flags_set (ID: 03300002)
Default Severity WARNING
Log Message The TCP <good_flag> and <bad_flag> flags are set. Stripping
<bad_flag> flag
Explanation The possible combinations for these flags are: SYN URG, SYN PSH,
SYN RST, SYN FIN and FIN URG. Removing the "bad" flag.
Gateway Action strip_bad_flag
Recommended Action If any of these combinations should either be dropped or ignored,
specify this in configuration, in the "Settings" sub system.
Revision 1
Parameters good_flag
bad_flag
Context Parameters Rule Name
Packet Buffer
2.57.3. tcp_flag_set (ID: 03300003)
Chapter 2: Log Message Reference
592