Forum Discussion
Nom_55811
Nimbostratus
Sep 01, 2009nPath Triggering Router Intrusion Detection
Hi All,
We've recently deployed a pair of BIG-IP 1600's in a redundant configuration in front of our corporate web site. Since then, we've discovered several customers using Billion (ht...
hoolio
Cirrostratus
Sep 01, 2009It might help to have an idea of what the exact problem is before trying to modify the LTM configuration. You might try contacting billion to get details on the message. Here are a few related posts found searching for that log message:
TCP FIN?
http://www.dslreports.com/forum/remark,604069
Google cache of a billion's forum post:
http://209.85.229.132/search?q=cache:sbdNFyQ9nPMJ:au.billion.com/forums/index.php%3Fshowtopic%3D9643+Intrusion+TCP+FIN+scan%2817%29&cd=1&hl=en&ct=clnk&gl=uk
If this is caused by the server (or LTM) sending a FIN after the connection has already been closed, you might consider disabling Loose Close on the FastL4 profile. This is a stab in the dark as I'm not sure what triggers the error.
Aaron
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects