If you look at any of your SIM or IPS logs for any given TCP connection, you will probably notice tons of logs for the same traffic with different source ports.
Just pick a TCP connection, note the source and destination IP, and then run a search on it. I am betting you will see pages of the same connection show up and some may be logged 5 times in the same second.
Why is that? Why do most devices send so much junk traffic when you turn on sysloging?
All i'm looking for is some explanations.