Short Name |
TCP:AUDIT:UNSOL-SACKPERM |
---|---|
Severity |
Info |
Recommended |
No |
Category |
TCP |
Keywords |
SYN-ACK SACKPERM TCP option |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This protocol anomaly triggers when it detects a SACKPERM option in a SYN-ACK packet, even though the client did not specify SACKPERM in the SYN packet. Because these ambiguous packets can be interpreted by the receiving TCP stack in different, unpredictable ways, it is recommended to drop them.
None