cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1678
Views
0
Helpful
1
Replies

illegal tcp flags

rnaydenov
Level 1
Level 1

Hi,

Recently on my servers I've been seeing some events generated by the Cisco Security Agent (4.5.1-616), which say:

Illegal TCP reserved flags set

I,ve attached one such log. Can someone say exactly what is wrong with this?

1 Reply 1

pciaccio
Level 4
Level 4

from you r log I see on your flags that it is set for Ack and Push. From the log this is a SMTP protocol. My guess is that your mail server is trying to push (Process the user data ASAP) this Ack and your security agent does not allow it or like the process. This may be a security agent configuration issue that you will have to investigate further.