I am a network newbie and got a question on FWSM (Version 3.2(7)). Does the FWSM by default drops duplicate SYN packet on a TCP 3 way handshake? The traffic is between the internal and external interface.
Solved! Go to Solution.
Why would you like to drop this dupplicate SYN packets, this could cause problems if there are some SYN packets getting lost ( connections will never be stablished)
The problem is the duplicate SYN packets are being dropped by the FWSM and caused peer reset on FTP sessions. I just want to make sure no one configured the FWSM to drop the duplicate SYN packet.
In fact The FWSM is not able to drop dupplicate SYN packets, there is no command for that!
An IPS could drop these packets but an ASA or FWSM will not drop them as this is not a security threath,