Link to home
Start Free TrialLog in
Avatar of yodaa
yodaa

asked on

Firewall Settings Alert Possible TCP Flood on IF X2

Guys could you help me with

What does  it mean ? What to do ?

09:49:17 Apr 20 1370 Firewall Settings Alert Possible TCP Flood on IF X2 - from machine xx:xx:99:17:3f:bf has ceased 192.168.0.155, 65031, X0 23.74.44.108 80 tcp

09:49:14 Apr 20 1369 Firewall Settings Alert Possible TCP Flood on IF X2 - src: 92.123.72.94:80 dst: My external IP:61488 92.123.72.94, 80, X2 My external IP , 61488, X2 tcp

Pleae help
Avatar of Sudeep Sharma
Sudeep Sharma
Flag of India image

This may (it might be genuine traffic) means that you have set the limit on the traffic passing from and to port 80 and hence you are getting those in the logs. In technical terms throttling is done on port 80.

What make and model is of the firewall?

Sudeep
Avatar of yodaa
yodaa

ASKER

Sonic wall tz 210
Do you have security module licensed with the firewall?
IPS/AntiVirus/AntiSpam, GeoIP Filter, Content Filter enabled?

Sudeep
Avatar of yodaa

ASKER

Yes we do
ASKER CERTIFIED SOLUTION
Avatar of Sudeep Sharma
Sudeep Sharma
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial