<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi,This means that Firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/security-breach/m-p/2685985#M190806</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;This means that Firewall is dropping an out-of-order packet. This shows firewall is working fine. There might be a lot of tcp out-of-order packets coming on the firewall and tcp reassembly buffer might&amp;nbsp;getting filled up.&lt;/P&gt;&lt;P&gt;Default Queue length&amp;nbsp;is 16 per session. You could try increasing the queue length,&amp;nbsp;timeout value and see if you still receive&amp;nbsp;these logs&amp;nbsp;or else you need to&amp;nbsp;look for reason for out-of-order packets in your network.&lt;/P&gt;&lt;P&gt;Go through the below link. It would give you detail understanding of the issue and configuration assistance :&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/ios/12_4t/12_4t11/ht_ooop.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if you have any query on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Akshay Rastogi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jun 2015 05:30:51 GMT</pubDate>
    <dc:creator>Akshay Rastogi</dc:creator>
    <dc:date>2015-06-11T05:30:51Z</dc:date>
    <item>
      <title>Security breach</title>
      <link>https://community.cisco.com/t5/network-security/security-breach/m-p/2685984#M190805</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I just setup a firewall on a series 800 router and shortly after the following message was displayed;&lt;/P&gt;&lt;P&gt;Jun 10 00:11:32.814: %FW-4-TCP_OoO_SEG: Dropping TCP Segment: seq:1890440221 146&lt;BR /&gt;0 bytes is out-of-order; expected seq:1890416081. Reason: TCP reassembly queue o&lt;BR /&gt;verflow - session my_internal_ip:53513 to intercepted_ip:80&lt;/P&gt;&lt;P&gt;Does this mean the firewall is doing it's job, and has disallowed access, or does this mean my&lt;/P&gt;&lt;P&gt;configuration is incorrect?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:04:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-breach/m-p/2685984#M190805</guid>
      <dc:creator>digbym650</dc:creator>
      <dc:date>2019-03-12T06:04:34Z</dc:date>
    </item>
    <item>
      <title>Hi,This means that Firewall</title>
      <link>https://community.cisco.com/t5/network-security/security-breach/m-p/2685985#M190806</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;This means that Firewall is dropping an out-of-order packet. This shows firewall is working fine. There might be a lot of tcp out-of-order packets coming on the firewall and tcp reassembly buffer might&amp;nbsp;getting filled up.&lt;/P&gt;&lt;P&gt;Default Queue length&amp;nbsp;is 16 per session. You could try increasing the queue length,&amp;nbsp;timeout value and see if you still receive&amp;nbsp;these logs&amp;nbsp;or else you need to&amp;nbsp;look for reason for out-of-order packets in your network.&lt;/P&gt;&lt;P&gt;Go through the below link. It would give you detail understanding of the issue and configuration assistance :&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/ios/12_4t/12_4t11/ht_ooop.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if you have any query on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Akshay Rastogi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2015 05:30:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-breach/m-p/2685985#M190806</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-06-11T05:30:51Z</dc:date>
    </item>
  </channel>
</rss>

