[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[firestorm053] tcp reassembly question



Hi,

I receive this event :

Jun 18 15:03:49 xxx 11 firestorm-nids053: 1055941429.164894
alert=tcpstream sig=4.0 priority=5 src=64.94.50.88 dst=217.128.40.92
proto=6 spt=80 dpt=34037 flags=****A*** from=server server=ESTABLISHED
client=ESTABLISHED : Reassembly Error

Download tcpdump file on this link : (3Mo)
http://crusoecids.dyndns.org/cyberguard-firestorm_reassemblyerror.tcpdump.gz

Yes ip 64.94.50.88 is web site Cyberguard.com,
and my ip dynamic

What is Reassembly Error ?
is timeout Error ?
other ?

Thanks for your Answers

Regard.

PS: I use firestorm-nids with syslog patch ...