<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Half-Syn open in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/half-syn-open/m-p/351585#M97654</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The engine for the Half-open Syn attack is 'Other' and the VMS tells me, that "Tunning of this signature engine is currently not supported".&lt;/P&gt;&lt;P&gt;?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 05 Dec 2004 22:23:48 GMT</pubDate>
    <dc:creator>teperjesi</dc:creator>
    <dc:date>2004-12-05T22:23:48Z</dc:date>
    <item>
      <title>Half-Syn open</title>
      <link>https://community.cisco.com/t5/network-security/half-syn-open/m-p/351581#M97650</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Can somebody tell me, if the Half-Syn open will fire only, when the client doesn't send the final handshake ACK or it fires when the server doens't send the SYN,ACK packet too?&lt;/P&gt;&lt;P&gt;Can somebody tell me the treshold value-s for this signature? I meen, how long the IDS waits, befor rates it as a Syn attack?&lt;/P&gt;&lt;P&gt;It is true, that I can tunning this signature?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regard:&lt;/P&gt;&lt;P&gt;Tamas&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:10:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/half-syn-open/m-p/351581#M97650</guid>
      <dc:creator>teperjesi</dc:creator>
      <dc:date>2019-03-10T09:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: Half-Syn open</title>
      <link>https://community.cisco.com/t5/network-security/half-syn-open/m-p/351582#M97651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think it fireup if server doesnot get the final ACK back from the client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the IDS doesnot see "SYN - ACK" then, it is SYN attack.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The thresholds can be changed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Dec 2004 19:57:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/half-syn-open/m-p/351582#M97651</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2004-12-05T19:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: Half-Syn open</title>
      <link>https://community.cisco.com/t5/network-security/half-syn-open/m-p/351583#M97652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;thanks for the answer.&lt;/P&gt;&lt;P&gt;Can you tell me, how can i adjust the thresholds?&lt;/P&gt;&lt;P&gt;Can I made this through VMS or CLI?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards:&lt;/P&gt;&lt;P&gt;Tamas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Dec 2004 21:09:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/half-syn-open/m-p/351583#M97652</guid>
      <dc:creator>teperjesi</dc:creator>
      <dc:date>2004-12-05T21:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: Half-Syn open</title>
      <link>https://community.cisco.com/t5/network-security/half-syn-open/m-p/351584#M97653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if you use VMS to manage the sensors, then adjust those thresholds from VMS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Dec 2004 21:25:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/half-syn-open/m-p/351584#M97653</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2004-12-05T21:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: Half-Syn open</title>
      <link>https://community.cisco.com/t5/network-security/half-syn-open/m-p/351585#M97654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The engine for the Half-open Syn attack is 'Other' and the VMS tells me, that "Tunning of this signature engine is currently not supported".&lt;/P&gt;&lt;P&gt;?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Dec 2004 22:23:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/half-syn-open/m-p/351585#M97654</guid>
      <dc:creator>teperjesi</dc:creator>
      <dc:date>2004-12-05T22:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: Half-Syn open</title>
      <link>https://community.cisco.com/t5/network-security/half-syn-open/m-p/351586#M97655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i am using IDSMC 2.0 and i am able to tune this signature. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Dec 2004 23:05:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/half-syn-open/m-p/351586#M97655</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2004-12-05T23:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: Half-Syn open</title>
      <link>https://community.cisco.com/t5/network-security/half-syn-open/m-p/351587#M97656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is very interesting, as I am able to confirm that it was not possible tune the &amp;#147;other engine&amp;#148; in version 1.2 of the IDSMC. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps someone can confirm this for me but I think that one thing to make especially sure of with this signature is that you do not have duplicate SYN requests with single Syn-Ack replies or even &amp;#147;no replies&amp;#148; in the data that you are sending to the monitor interface of the SPAN session as this could also lead to problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;#147;Duplicate Traffic&lt;/P&gt;&lt;P&gt;In some configurations, SPAN sends multiple copies of the same source traffic to the destination port. For example, in a configuration with a bidirectional SPAN session (both ingress and egress) for two SPAN sources, called s1 and s2, to a SPAN destination port, called d1, if a packet enters the switch through s1 and is sent for egress from the switch to s2, ingress SPAN at s1 sends a copy of the packet to SPAN destination d1 and egress SPAN at s2 sends a copy of the packet to SPAN destination d1. If the packet was Layer 2 switched from s1 to s2, both SPAN packets would be the same. If the packet was Layer 3 switched from s1 to s2, the Layer-3 rewrite would alter the source and destination Layer 2 addresses, in which case the SPAN packets would be different.&amp;#148;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reference: &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/switches/ps708/products_configuration_guide_chapter09186a0080179597.html#1040560" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/switches/ps708/products_configuration_guide_chapter09186a0080179597.html#1040560&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Dec 2004 16:35:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/half-syn-open/m-p/351587#M97656</guid>
      <dc:creator>darin.marais</dc:creator>
      <dc:date>2004-12-06T16:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: Half-Syn open</title>
      <link>https://community.cisco.com/t5/network-security/half-syn-open/m-p/351588#M97657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This question is related to Half-open Syn and if anyone has experienced anything issues or false-positives with Cisco CSS?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jan 2005 16:38:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/half-syn-open/m-p/351588#M97657</guid>
      <dc:creator>nickbruno</dc:creator>
      <dc:date>2005-01-05T16:38:30Z</dc:date>
    </item>
  </channel>
</rss>

