Access the answers to your technology questions today.
Subscribe Now
30-day free trial. Register in 60 seconds.
What Makes Experts Exchange Unique?
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.
Try it out and discover for yourself.
Subscribe Now
30-day free trial. Register in 60 seconds.
Join the Community
Give a Little. Get a Lot.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Join the Community
by: mohawk1Posted on 2006-08-09 at 07:38:59ID: 17279294
Hi,
Just decoding the messages for you:
1. %FW-4-HOST_TCP_ALERT_ON: Max tcp half-open connections ([dec]) exceeded for host [IP_address].
The max-incomplete host limit of half-open TCP connections has been exceeded. This message indicates that a high number of half-open connections is coming to the protected server, and it may indicate that a SYN flood attack is in progress and is targeted to the specified server host.
Recommended Action: This message is for informational purposes only, but it may indicate that a SYN flood attack was attempted. If this alert is issued frequently and identified to be mostly false alarms, then the max-incomplete host threshold value is probably set too low, and there is a significant amount of legitimate traffic coming into that server. In this case, the max-incomplete host parameter should be set to a higher number to avoid false alarms.
Related documents- No specific documents apply to this error message.
2. %FW-4-ALERT_ON: [chars], count ([dec]/[dec]) current 1-min rate: [dec]
Either the max-incomplete high threshold of half-open connections or the new connection initiation rate has been exceeded. This error message indicates that an unusually high rate of new connections is coming through the firewall, and a DOS attack may be in progress. This message is issued only when the max-incomplete high threshold is crossed.
Recommended Action: This message is for informational purposed only, but it may indicate a security problem.
Related documents- No specific documents apply to this error message.
It looks like something is trying to hack you. Switch on ip-accounting initially.
Regards
Mohawk1