Options

TCP Invalid connection state

Using Firebox M440 version 12.6.2. I'm seeing a lot of tcp invalid connection state messages in my traffic monitor. Are these important? This firewall is not for internet traffic. It is firewalling our internal subnets. Here are a couple of samples. In one, the destination is external and the port is 443. On the 2nd one, it's internal windows traffic going from one subnet to another:

2020-12-18 08:38:40 FireboxM440Primary Deny 10.x.x.x 18.214.41.116 https/tcp 44170 443 Datacenter Firebox tcp invalid connection state 40 64 (Internal Policy) proc_id="firewall" rc="101" msg_id="3000-0148" tcp_info="offset 5 R 43179066 win 0" Traffic

2020-12-18 08:28:24 FireboxM440Primary Deny 10.x.15.x. 10.x.13.x 51281/tcp 445 51281 Loans Bookkeeping tcp invalid connection state 40 128 (Internal Policy) proc_id="firewall" rc="101" msg_id="3000-0148" tcp_info="offset 5 R 2049075505 win 0" Traffic

Thanks,

Mike

Comments

Sign In to comment.