cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1962
Views
0
Helpful
1
Replies

Duplicate TCP SYN from outside

jovan074
Level 1
Level 1

Hi guys, recently my logs from Firepower are filled with msg:  %FTD-4-419002: Duplicate TCP SYN from outside-x.x.x.x/xx to nlp_int_tap:(MY STATIC IP-from ISP/443) with different initial sequence number.

So outside IPs and ports are random, i was reading forums, and as far as i udnderstood it could be SYN-ACK flood attack, but on cisco system message logging it says "Recommended action: None required".

Also i have no problems with any services on my private network, my VPN clients works fine, though im still concerned about whats going on because theres large amount of those logs per day. If someone can explain me what those logs exactly mean and do i need to take some action i would be thankful.

 

 

 

 

 

1 Reply 1
Review Cisco Networking for a $25 gift card