10-29-2012 02:29 PM - edited 03-11-2019 05:15 PM
Hi,
I am a network newbie and got a question on FWSM (Version 3.2(7)). Does the FWSM by default drops duplicate SYN packet on a TCP 3 way handshake? The traffic is between the internal and external interface.
Thanks,
Network Newbie
Solved! Go to Solution.
10-29-2012 02:34 PM
Hello Danny Lee,
No, it does not.
By default it will not drop it, It will report it but it will not drop it
Hope I could help,
Regards
10-29-2012 02:34 PM
Hello Danny Lee,
No, it does not.
By default it will not drop it, It will report it but it will not drop it
Hope I could help,
Regards
10-30-2012 08:02 AM
Hi,
What is the command to enable the dropping of duplicate SYN packet by the FWSM.
Thanks,
Network Newbie
10-30-2012 09:31 AM
Hello Danny,
Why would you like to drop this dupplicate SYN packets, this could cause problems if there are some SYN packets getting lost ( connections will never be stablished)
Regards,
Julio
10-30-2012 09:36 AM
Hi Julio,
The problem is the duplicate SYN packets are being dropped by the FWSM and caused peer reset on FTP sessions. I just want to make sure no one configured the FWSM to drop the duplicate SYN packet.
Thanks,
Dan
10-30-2012 10:08 AM
Hello Danny,
In fact The FWSM is not able to drop dupplicate SYN packets, there is no command for that!
An IPS could drop these packets but an ASA or FWSM will not drop them as this is not a security threath,
Regards,
Julio
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide