Dear Team,
Query 1: is this a default protection (Part of the access control policy) ?
Query 2: Why does GW send traffic to its own using Mgmt Port?
Query 3: What is the impact ?
Attack Name: Mailformed Packet
Attack Information: Invalid TCP flag combination
Protection Type: Protocol Animaly
Performance Impact: Very Low
Confidence Level: High
Severity:Medium
Industry reference: CAN-2002-1071
tcp_flags:PUSH-URG
Interface: Mgmt
interface Direction: Inbound
SRC IP: GW (10.10.10.2)
DST IP:GW (10.10.10.2)
Service: TCP/46039 (Destination Port)
Protocol: TCP (6) (6)
Threat Profile: No_protection_503******
Action: Detect