cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
246
Views
0
Helpful
2
Replies

CSA and "ephemeral"

chris.poulin
Beginner
Beginner

Does anyone have a more clear explanation about the difference between, for example, "TCP/ephemeral" and "TCP/1024-65535" in CSA? The only clear distinction in the help text is that "Ephemeral ports are treated as "port 0" for rule comparisons."

2 Replies 2

umedryk
Contributor
Contributor

Ephemeral is a separate entry. tdiflag=4 means it is an ephemeral port being used. The problem is the event tells you the actual port that is used even though the system designated an ephemeral port.

Thanks for your response, Ursula. But what does that mean functionally? What is the operational distinction between "ephemeral" and "TCP/1024-65535" (or UDP/1024-65535)?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers