Tuesday, February 12, 2019

Duplicate TCP SYN

My ASDM log is full of these with varying source IP, but all go to destination 192.168.0.1, which is not an IP, object, interface, or subnet we use. I can't find any reason for that to be a destination port unless it is on by default and the firewall doesn't know what to do with it so it dumps the SYN. SYN attack for 10-min and 1-hour is 200+

4 Feb 12 2019 14:34:13 192.168.100.87 54785 192.168.0.1 49152 Duplicate TCP SYN from inside:192.168.100.87/54785 to inside:192.168.0.1/49152 with different initial sequence number

4 Feb 12 2019 14:35:42 [ 192.168.101.179] drop rate-1 exceeded. Current burst rate is 0 per second, max configured rate is 10; Current average rate is 18 per second, max configured rate is 5; Cumulative total count is 22279

Any idea why my objects are sending packets to 192.168.0.1, which shouldn't exist?



No comments:

Post a Comment