Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
jamal_shah
Participant

TCP packet out of state: First packet isn't SYN TCP Flags: SYN-ACK

Hi,

I am getting this error in the Firewall logs.

Can someone please advise.

Thanks

 

 

0 Kudos
3 Replies
Chris_Atkinson
Employee Employee
Employee

Could be due to aggressive aging if the memory consumption is high?

Other possibilities may include:

- Connection persistence as relevant to policy install

- Asymmetric routing

 

CCSM R77/R80/ELITE
0 Kudos
the_rock
Legend
Legend

I agree with @Chris_Atkinson . That sort of message is asymmetric routing literally 9 times out of 10. Please do fw monitor capture and see what it shows.

Andy

0 Kudos
Timothy_Hall
Legend Legend
Legend

As other posters have observed this is generally caused by asymmetric routing.  However it can also occur in cases where the amount of time between the SYN and SYN-ACK exceeds the default TCP start timeout of 25 seconds, caused by high packet loss or extreme network congestion.  While exceeding 25 seconds for this simple exchange seems impossible, keep in mind that if Aggressive Aging is active this timer will be reduced to 5 seconds which is much more plausible.  

If Aggressive Aging seems to be constantly active on the firewall for no obvious reason, it is usually due to memory issues on non-VSX firewalls as mentioned in the free addendum for the third edition of my Max Power book:

Aggressive_Aging.png

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events