Knowledge Search


×
 

SYN and FIN Bit Set at the Same Time

  [KB5801] Show Article Properties


Summary:
SYN and FIN Bit Set at the Same Time
Symptoms:
Symptoms & Errors:
  • Alarm event log: 2002-08-27 02:30:31 system-critical-00437: SYN & FIN set, From a.b.c.d/y to e.f.g.h/y, using protocol TCP (on interface ethernet2)
  • SYN and FIN Bit Set at the Same Time

Solution:

An application that sends a SYN and FIN bit at the same time is considered an illegal packet, which is used by hackers to provide a Denial of Service (DoS) on systems.  Since this is considered an attack, NetScreen reports it, and drops the packet.

The RFC for TCP does not support a SYN and FIN in the same packet.  If an application is sending this, it isn't following the RFC standards.

Related Links: