From owner-freebsd-net@FreeBSD.ORG Fri Jun 8 01:30:54 2012 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 89108106566C for ; Fri, 8 Jun 2012 01:30:54 +0000 (UTC) (envelope-from adrian.chadd@gmail.com) Received: from mail-pb0-f54.google.com (mail-pb0-f54.google.com [209.85.160.54]) by mx1.freebsd.org (Postfix) with ESMTP id 5BB7E8FC0A for ; Fri, 8 Jun 2012 01:30:54 +0000 (UTC) Received: by pbbro2 with SMTP id ro2so1971732pbb.13 for ; Thu, 07 Jun 2012 18:30:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:cc:content-type; bh=psYWll1/nuDasKIrBWbI99UyrTuFdMHULaXYNE3sgXA=; b=SiEPAMc0PVCoYWUhql3SIHKD3cRH7Fe+gebkwNaO4kmOLH0jlOwX2mQ3hlc+/D3I0/ oUgY2IPGTtCzj/wxPNpkWcB/KbBl80iMEst0Q7SKFcHARIsLjDg726CZRjKL21DpxlVH WubkqByS831cQbBIDU9SClOF0XCFlK8H77w7BsAIunr9Dyi9Of1x3p5vn5bRkiME5oEy zjqmAxUEkfa+UT/z5rwDLW7tHD7xvwnElrN5wr8NI2W4PZem6ho+RmkXR8KRYyGEx1W0 EOiMCpAvw0Uoy6GOZULgJnzqf3XdvvXYNdPsGcRxBqZsrejXegVb8XGEvzgPOEmP6U5J iM+g== MIME-Version: 1.0 Received: by 10.68.234.35 with SMTP id ub3mr15658195pbc.8.1339119054000; Thu, 07 Jun 2012 18:30:54 -0700 (PDT) Sender: adrian.chadd@gmail.com Received: by 10.143.91.18 with HTTP; Thu, 7 Jun 2012 18:30:53 -0700 (PDT) In-Reply-To: <54EF0399-B36E-42CA-9526-DDC7ADA4406A@gmail.com> References: <54EF0399-B36E-42CA-9526-DDC7ADA4406A@gmail.com> Date: Thu, 7 Jun 2012 18:30:53 -0700 X-Google-Sender-Auth: V1SPLn2hnWDbfqZtGOOCkIMToEw Message-ID: From: Adrian Chadd To: Nikolay Denev Content-Type: text/plain; charset=ISO-8859-1 Cc: freebsd-net Subject: Re: FreeBSD 8.2-STABLE sending FIN no ACK packets. X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 08 Jun 2012 01:30:54 -0000 On 7 June 2012 05:41, Nikolay Denev wrote: > Hello, > > I've been pointed out by our partner that we are sending TCP packets with FIN flag and no ACK set, which is triggering > alerts on their firewalls. > I've investigated, and it appears that some of our FreeBSD hosts are really sending such packets. (they are running some java applications) > I did "tcpdump -s0 -vni em1 '(tcp[tcpflags] & tcp-ack == 0) && (tcp[tcpflags] & tcp-fin != 0)'" to catch them. > > Is this considered normal? > It seems at least Juniper considers this malicious traffic : http://www.juniper.net/techpubs/software/junos-security/junos-security10.0/junos-security-swconfig-security/id-72577.html Would you please file a PR with this, so it doesn't get lost? Thanks, Adrian