Does anyone have a more clear explanation about the difference between, for example, "TCP/ephemeral" and "TCP/1024-65535" in CSA? The only clear distinction in the help text is that "Ephemeral ports are treated as "port 0" for rule comparisons."
Ephemeral is a separate entry. tdiflag=4 means it is an ephemeral port being used. The problem is the event tells you the actual port that is used even though the system designated an ephemeral port.
Thanks for your response, Ursula. But what does that mean functionally? What is the operational distinction between "ephemeral" and "TCP/1024-65535" (or UDP/1024-65535)?
Getting Started
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: