cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
336
Views
0
Helpful
2
Replies

dropped packets with source port 0

lubo.nistor
Level 1
Level 1

I've just experienced a X11 communication where xdm direct advertisment went through, but the resulting x11 communication was dropped by pix 515 6.3(4). I noticed that the dropped packet had a source port 0 otherwise it looked fine..

As a note: direct X11 packets with EXPORT DISPLAY work fine.

Q: is there a way to change this PIX-OS behavior dropping strange looking packets?

2 Replies 2

ssoberlik
Level 4
Level 4

The issue is that the PIX follows the convention that port 0 is to mean all port. Therefore, if the PIX accept a packet with source port 0, then all ports of the sending host are considered to be open.

Which I guess is a security Loophole.

nope:

-the message comes from log.

-it is a source port

-there's no rule like that in the access list.

the only reasonable explanation is that there's a general protocol analysis and it doesn't like source port 0.

but the question is can it be changed?