Dear All,
Our company have 100 users, in recent network was very slow, I log on edge router to show logging command, display as below:
I want to know whether our network have some attack? and what should I to do?
Our topology is: ISP------2900---------3750---------2960 STACK *3
Thanks in advance!
May 16 08:12:45.829: %FW-3-RESPONDER_WND_SCALE_INI_NO_SCALE: Dropping packet - Invalid Window Scale option for session 10.24.246.53:55530 to 58.221.72.180:80 [Initiator(flag 0,factor 0) Responder (flag 1, factor 9)]
May 16 08:13:55.969: %FW-4-TCP_OoO_SEG: Dropping TCP Segment: seq:2102491905 1064 bytes is out-of-order; expected seq:2102404865. Reason: TCP reassembly queue overflow - session 10.24.246.44:64405 to 140.207.195.36:80
May 16 08:14:43.604: %FW-3-RESPONDER_WND_SCALE_INI_NO_SCALE: Dropping packet - Invalid Window Scale option for session 10.24.246.53:55552 to 58.221.72.180:80 [Initiator(flag 0,factor 0) Responder (flag 1, factor 9)]
May 16 08:15:07.972: %FW-4-ALERT_OFF: calming down, count (46/900) current 1-min rate: 1796
May 16 08:15:10.344: %FW-4-ALERT_ON: getting aggressive, count (56/1000) current 1-min rate: 2001