<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TCP Window Variation Sig fires repeatedly in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tcp-window-variation-sig-fires-repeatedly/m-p/1343696#M68656</link>
    <description>&lt;P&gt;Sig 1307/0 TCP Window Variation is constantly firing on my IPS.  The explanation mentions that some "improperly implemented" firewalls can cause this signature to fire.  I have an ASA 5520 between my users and the internet and all internet traffic is NATed.  It fires on normal web traffic to known good sites as well as traffic between sites coming in over IPSEC VPN, which is exempted from NAT.  Any ideas on what may be causing this?&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 11:45:36 GMT</pubDate>
    <dc:creator>jms112080</dc:creator>
    <dc:date>2019-03-10T11:45:36Z</dc:date>
    <item>
      <title>TCP Window Variation Sig fires repeatedly</title>
      <link>https://community.cisco.com/t5/network-security/tcp-window-variation-sig-fires-repeatedly/m-p/1343696#M68656</link>
      <description>&lt;P&gt;Sig 1307/0 TCP Window Variation is constantly firing on my IPS.  The explanation mentions that some "improperly implemented" firewalls can cause this signature to fire.  I have an ASA 5520 between my users and the internet and all internet traffic is NATed.  It fires on normal web traffic to known good sites as well as traffic between sites coming in over IPSEC VPN, which is exempted from NAT.  Any ideas on what may be causing this?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:45:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-window-variation-sig-fires-repeatedly/m-p/1343696#M68656</guid>
      <dc:creator>jms112080</dc:creator>
      <dc:date>2019-03-10T11:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Window Variation Sig fires repeatedly</title>
      <link>https://community.cisco.com/t5/network-security/tcp-window-variation-sig-fires-repeatedly/m-p/1343697#M68657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This signature Sig 1307/0 will fire when the TCP window varies in a suspect manner. The right edge of the recieve window for TCP decreases. The TCP RFCs state that this should not occur.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This signature will NOT function in promiscuous mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some incorrectly implemented proxies or network address translation firewalls could modify the window can cause this signature to fire.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Sep 2009 12:50:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-window-variation-sig-fires-repeatedly/m-p/1343697#M68657</guid>
      <dc:creator>smalkeric</dc:creator>
      <dc:date>2009-09-15T12:50:37Z</dc:date>
    </item>
  </channel>
</rss>

