Support Support Downloads Knowledge Base Juniper Support Portal Community

Knowledge Base

Search our Knowledge Base sites to find answers to your questions.

Ask All Knowledge Base Sites All Knowledge Base Sites JunosE Defect (KA)Knowledge BaseSecurity AdvisoriesTechnical BulletinsTechnotes Sign in to display secure content and recently viewed articles

[ScreenOS] What is required for the TCP-RST packet to be returned by the NS firewall, when no session table entries are present and a non tcp-syn packet is received?

0

0

Article ID: KB6767 KB Last Updated: 06 Nov 2012Version: 5.0
Summary:
This article provides information about the requirement for the TCP-RST packet to be returned by the NS firewall, when no session table entries are present and a non TCP-SYN packet is received.
Symptoms:
Requirement for the TCP-RST packet to be returned by the NS firewall, when no session table entries are present and a non TCP-SYN packet is received.
Cause:

Solution:
A TCP session entry will be cleared, when the outgoing physical interface or the tunnel interface that the session is using is disconnected.
 
When the set flow tcp-syn-check and set zone <zone> tcp-rst commands are configured, the firewall will check if the TCP packet is a SYN packet; if it is not a SYN packet, then a TCP-RST is returned to the originating host.
Comment on this article > Affected Products Browse the Knowledge Base for more articles related to these product categories. Select a category to begin.

Getting Up and Running with Junos

Getting Up and Running with Junos Security Alerts and Vulnerabilities Product Alerts and Software Release Notices Problem Report (PR) Search Tool EOL Notices and Bulletins JTAC User Guide Customer Care User Guide Pathfinder SRX High Availability Configurator SRX VPN Configurator Training Courses and Videos End User Licence Agreement Global Search