Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
JPR
Contributor

"CPNotEnoughDataForRuleMatch" and "Connection terminated..."

Hi all,

I am seeing a lot of “Connection terminated before detection: Insufficient data.”  and “Connection terminated before detection: No SSL applicative data.“ and the matched rule “CPNotEnoughDataForRuleMatch” on my gateway and it worries me a little.

When I perform a simple search for logs with those fields in combination in our SIEM in 24 hour time frame I get quite a lot as seen below:

cp1.png

I've checked out the sk113479 and it states that: “No fix is required. This behavior is by design.”, but I still find it a bit odd.

Below is an actual log from the gateway:

cp2.png

And the matched rule:

cp3.png

The gateway seems to work as it should, but it just seems as a fairly large amount of hits and I’m just worried we have some kind of misconfiguration on our gateway.

Appliance is 6400 running 81.20 Take 84.

Any comments or ideas are welcome!

Thanks.

0 Kudos
5 Replies
PhoneBoy
Admin
Admin

The reason this occurs is simple: some level of rulebase matching must occur on the first packet.
All you know from the initial TCP SYN for policy matching purposes is:

  • Source IP
  • Destination IP
  • Destination Port Number

Knowing the exact applications used requires allowing some additional packets after the three-way handshake.
If the connection terminates before that determination is done (usually doesn't take more than a few packets), you'll see this error.

Like the SK says, it's perfectly normal, expected behavior.

the_rock
Legend
Legend

Here is, in my opinion, the BEST explanation for it, provided by @Bob_Zimmerman in 2nd link I gave you.

Andy

 

This message means the firewall isn't the problem. It allowed the SYN, but the connection was closed for some other reason before the firewall could see the website or application being attempted.

This is almost always because the server didn't respond with a SYN-ACK.

JPR
Contributor

Okay, thanks to you both. That calms my nerves a lot 🙂

So in your opinion I shouldn't be alarmed about the amount logs regarding this either? We're a company of around 650 internal users.

0 Kudos
the_rock
Legend
Legend

I dont think you should be.

Andy

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events