Compare System Log Messages
Compare system log messages in two different software releases.
Select two Releases to Compare
Unique system log messages in
Unique system log messages in
Unique system log messages in
Unique system log messages in
Common log messages
No information available.
ASP_SFW_SYN_DEFENSE
Filter Releases
Specific system log message Information:
Name
ASP_SFW_SYN_DEFENSE
Message
<variable>syslog-prefix</variable> <variable>error-code</variable>: proto <variable>protocol-id</variable> (<variable>protocol-name</variable>), <variable>source-interface-name</variable><variable>separator</variable><variable>source-address</variable>:<variable>source-port</variable> -> <variable>destination-address</variable><variable>destination-port</variable>, <variable>event-type</variable>
Help
TCP handshake timed out for session
Description
The stateful firewall discarded the packet with the indicated characteristics, because the Transmission Control Protocol (TCP) handshake that is used to establish a session did not complete quickly enough. The time limit is set by the 'open-timeout' statement at the [edit interfaces <services-interface> services-options] hierarchy level or is four seconds by default. The event was reported to intrusion detection services (IDS) and can cause IDS to activate SYN cookie protection. The discarded packet contained the indicated information about its protocol (numerical identifier and name), source (logical interface name, IP address, and port number), and destination (IP address and port number).
Type
Event: This message reports an event, not an error
Severity
notice
Cause
Possible causes for the handshake failure include the following: (1) sequence numbers did not match in a SYN packet and a previous SYN packet (the second packet was not a retransmission) (2) sequence numbers did not match in a SYN/ACK packet and a previous SYN packet (3) either or both a SYN/ACK packet and an ACK packet did not arrive at the firewall within the time limit.
Facility
LOG_PFE
Action
Attributes
syslog-prefix
error-code
protocol-id
protocol-name
source-interface-name
separator
source-address
source-port
destination-address
destination-port
event-type
ASP_SFW_SYN_DEFENSE available in the following releases: