besmile4ever
asked on
SYN flood! From juniper firewall...how to fix it.
Hi ,
My firewall ISG1000 is keep sending SYN Flood to my log server when I enable the logs...is there any explanation to what happened and how to fix it?
My firewall ISG1000 is keep sending SYN Flood to my log server when I enable the logs...is there any explanation to what happened and how to fix it?
if i'm not wrong , isg 1000 has the option to use TCP or UDP syslog. maybe u can try the UDP syslog
ASKER
ok..how can I set the UDP syslog?
ASKER
when I enable it on port 514 from the GUI and choosing only event log and traffic log..it still keep sending on TCP...
could you print screen and send to yuliang11@yahoo.com ?
tq
tq
ASKER
yep it is sent..
Cheers.
Cheers.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Many thnks..excellent response.
if it's the management IP address , it's possible that you have configured a SYN(TCP) log (syslog,eg) to the log server but the log server is maybe running in UDP syslog or something like that. You will see a lot of SYN with no 3 way handkshake as there are no real ports being opened on the log server.