<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What does this log message mean? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/what-does-this-log-message-mean/m-p/1091599#M892706</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Error Message    %PIX-4-209005: Discard IP fragment set with more than number elements: &lt;/P&gt;&lt;P&gt;src = IP_address, dest = IP_address, proto = protocol, id = number&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Explanation    Too many elements are in a fragment set. The firewall disallows any IP packet that is fragmented into more than 12 fragments. Refer to the fragment command in the Cisco PIX Firewall Command Reference for more information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recommended Action    A possible intrusion event may be in progress. If the message persists, contact the remote peer's administrator or upstream provider. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a look at &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/df.html#wp1029667" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/df.html#wp1029667&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Dec 2008 23:53:30 GMT</pubDate>
    <dc:creator>grant.maynard</dc:creator>
    <dc:date>2008-12-04T23:53:30Z</dc:date>
    <item>
      <title>What does this log message mean?</title>
      <link>https://community.cisco.com/t5/network-security/what-does-this-log-message-mean/m-p/1091598#M892699</link>
      <description>&lt;P&gt;I am having trouble with RDP through my LAN-to-LAN tunnel and I keep reciving the below message in my log.  Do you have any idea what could cause this message and how to fix it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;209005: Discard IP fragment set with more than 1 elements:  src = 196.12.47.50, dest = 174.18.22.22, proto = esp, id = 39374&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please note that I have changed the public IPs.  The first IP in the log represents the outside IP address of my PIX (6.3 5) and the 2nd one is the outside IP address of the termanating VPN conncetion (6.3 5).&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:21:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-does-this-log-message-mean/m-p/1091598#M892699</guid>
      <dc:creator>anowell</dc:creator>
      <dc:date>2019-03-11T14:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: What does this log message mean?</title>
      <link>https://community.cisco.com/t5/network-security/what-does-this-log-message-mean/m-p/1091599#M892706</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Error Message    %PIX-4-209005: Discard IP fragment set with more than number elements: &lt;/P&gt;&lt;P&gt;src = IP_address, dest = IP_address, proto = protocol, id = number&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Explanation    Too many elements are in a fragment set. The firewall disallows any IP packet that is fragmented into more than 12 fragments. Refer to the fragment command in the Cisco PIX Firewall Command Reference for more information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recommended Action    A possible intrusion event may be in progress. If the message persists, contact the remote peer's administrator or upstream provider. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a look at &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/df.html#wp1029667" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/df.html#wp1029667&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Dec 2008 23:53:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-does-this-log-message-mean/m-p/1091599#M892706</guid>
      <dc:creator>grant.maynard</dc:creator>
      <dc:date>2008-12-04T23:53:30Z</dc:date>
    </item>
  </channel>
</rss>

