Link to home
Start Free TrialLog in
Avatar of besmile4ever
besmile4everFlag for Saudi Arabia

asked on

SYN flood! From juniper firewall...how to fix it.

Hi ,
My firewall ISG1000 is keep sending SYN Flood to my log server when I enable the logs...is there any explanation to what happened and how to fix it?
Avatar of yuliang11
yuliang11
Flag of Malaysia image

is the IP that is doing the syn flood the management IP address or is it a NAT ip address of the firewall?

 if it's the management IP address , it's  possible that you have configured a SYN(TCP) log (syslog,eg)  to the log server but the log server is maybe running in UDP syslog or something like that. You will see a lot of SYN with no 3 way handkshake as there are no real ports being opened on the log server.
if i'm not wrong , isg 1000 has the option to use TCP or UDP syslog. maybe u can try the UDP syslog
Avatar of besmile4ever

ASKER

ok..how can I set the UDP syslog?
when I enable it on port 514 from the GUI and choosing only event log and traffic log..it still keep sending on TCP...
could you print screen and send to yuliang11@yahoo.com ?

tq
yep it is sent..


Cheers.
ASKER CERTIFIED SOLUTION
Avatar of yuliang11
yuliang11
Flag of Malaysia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Many thnks..excellent response.