Signature 1330-X: TCP segment out of order - what does it mean?

Hi,
on a customer's site, on one of their IPS, I get a lot of sig 1330 alerts, mainly those two:
1330-12: TCP segment is out of order. If the signature status is set to disabled, the packet will be passed to all engines that are not stream based.
This signature will not produce an alert in promiscuous mode regardless of the signature status.
1330-17: TCP segment out of state order. If a packet in a stream causes this signature to produce an alert, processing will cease for that stream. This signature will not produce an alert in promiscuous mode regardless of the signature status
I'm not sure how to interpret these alerts correctly and/or how to troubleshoot further. Does anyone have an idea?
Thanks a lot,
Florian

Is your sensor monitoring more than one network segment?
If so then these alarms are common when a TCP connection crosses both networks and gets seen twice by the sensor.
This can confuse the sensor's tracking of the connection.
A common scenario is to have the sensor monitor both the Inside network or a firewall as well as the DMZ. When an internal user connects to the company's web server the traffic gets seen by the sensor both on the Inside network and in the DMZ. The sensor tries to put the packets from both networks together in order to try and monitor it as a single connection. Because the packets get modified by the firewall it often results in inconsitency between traffic on the 2 sides and causes the sensor to be confused about the connection.
The good news is that if this is your problem, then there are 2 easy workarounds.
1) If your sensor supports virtual sensors, then create a second virtual sensor. Assign one network to default vs0, and assign the other network to the new virtual sensor. This way each virtual sensor sees traffic on just one of the networks and won't become confused.
2) If your sensor does not support additional virtual sensors, or you've used up all 4 virtual sensors, then there is a configuration option within the virtual sensor configuration itself:
Inline TCP Session Tracking Mode
By default it is set to Virtual Sensor which is why it tries to put together packets from both networks to try and look at is a single connection and gets confused.
BUT it can also be set to Interface and Vlan. This configuration allows the virtual sensor to treat the traffic on each network independantly. The connection on the first network will be monitored independant of the connection on the second network. This will prevent the virtual sensor from getting confused.
The above is just my guess at what is going on in your network based on what we've seen on other networks. If this doesn't address the reason for the signature triggerings, then please respond back with more information about your network.
It is possible that these could be a hacker trying to avoid detection by the sensor, but more likely something in your deployment is confusing the sensor.

Similar Messages

  • HT2186 I just bought an iMac, while setting it up I was prompted to update the OS software. I tried to update it. It won't complete the update, and says "Error- requested timed out. (102) what does that mean? how do I fix it?

    I just bought an iMac, while setting it up I was prompted to update the OS software. I tried to update it. It won't complete the update, and says "Error- requested timed out. (102) what does that mean? how do I fix it?

    If you have more than one user account, these instructions must be carried out as an administrator.
    Launch the Console application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Console in the icon grid.
    Select "/var/log/install.log" from the file list on the left. If you don't see that list, select
    View ▹ Show Log List
    from the menu bar. Then select the messages from the last installation or update attempt, starting from the time when you initiated it. If you're not sure when that was, start over and note the time. Copy them to the Clipboard (command-C). Paste into a reply to this message (command-V).
    If there are runs of repeated messages, post only one example of each. Don’t post many repetitions of the same message.
    When posting a log extract, be selective. Don't post more than is requested.
    Please do not indiscriminately dump thousands of lines from the log into this discussion.
    Important: Some private information, such as your name, may appear in the log. Edit it out by search-and-replace in a text editor before posting.

  • Screen blacks out at startup; what does it mean and can I fix it?

    I've got a Macbook that has held up wonderfully over the past 6 months but just within the last week I've been having problems when trying to start my computer. I will turn it on like I normally do, the startup sound plays, the blue apple screen will come up and OS X will begin to load but then.....my screen goes black. Pressing keys does not make the screen come on and neither does working with the scroll pad. The computer is still on and running; putting it to my ear I can hear the hard drive running. I then have to force quit by holding down the power button to retry starting it again. The last time I tried to turn on my computer it took about 6 tries before I finally got into my account. After logging in it will run like it normally does and I have no problems. I know that this force quitting probably isn't helping the problem, and I want to get some advice from other apple owners before I run into the local mac store in tears. The computer was bought in December and I'm running Mac OS X.
    Any advice would be helpful and greatly appricated. Thanks!

    Maybe Disk Utility can repair the disk this way:
    -Search your installation DVD's.
    -Insert the disc 1 and sthut down your Mac
    -Start your Mac again while holding down the C key
    -Now your Mac should boot from the CD, this can take some time.
    -After a while you will see a installation screen where you can chose a language.
    -Chose English and continue.
    -Then click some time's next and agree with the "Software Agreement".
    -Open Disk Utility. Top menu bar --> Utilities --> Open Disk Utility.
    -Select your hard disk in the list of disks and volumes on the left side
    -Go to the First Aid (tab somewhere on the right).
    -Click the button to verify the permissions.
    -Then Click the button to repair the permissions.
    -Click the button to verify the disk.
    -Then Click the button to repair the disk.
    -Exit the Disk Utility and the installer.
    -Restart your Mac
    In any case,when you force shout down,Repair Disc Permissions.

  • My music is organized on my computer but the songs under the albums are out of order on my ipod, they weren't before, i've restored, still out of order. what do i do to get them in order?

    My music is organized on my computer but the songs under the albums are out of order on my ipod, they weren't before, i've restored, still out of order. what do i do to get them in order?

    Have you tried creating a playlist for your album, then
    select the playlist in iTunes.
    right-click the playlist name -> select +copy to play order+. -> sync.

  • I just bought a Mac today and have never had one, my Itunes shows to have all of my music on it but it won't allow me to play it out loud, it says my computer is not authorized? what does this mean?

    I'm a first time Mac user and I went to play my music on Itunes out loud and all the music I previously purchased will not play and then a pop up appears saying my computer is not authorized? what does this mean and how can I fix it?

    You need to authorize the new computer that youre working with. First hover over the store button at the top of the screen and then select the authorize this computer button then a popup will appear where you have to put in your Apple ID and Password. Hopefully this works for you

  • Why is the sound of my new ipad cutting out intermittently and what does Apple recommend to solve the problem in lieu of any updates?

    Why is the sound of my new ipad cutting out intermittently and what does Apple recommend to solve the problem in lieu of any updates? All of a sudden without changing any settings, the audio on my NEW ipad cuts in and out on applications/ games, keypad noise and lock sounds. The rocker button only seems to work while the sound is intermittently being heard before, after a few seconds of noise not doing anything when sound goes off.
    This is highly frustrating as I've noticed others posting about such issues as far back as April. Anybody had the same thing happen to them? Is this likely software (ios6) or hardware issue? What are the solutions Apple???

    Apple has no physical stores of their own in Dubai, so unless you mean that you purchased from the online Apple Store for the UAE, you purchased from a dealer, who may or may not have been authorized. You can check the expiration date of the warranty on your iPad yourself by entering in the serial number here:
    https://selfsolve.apple.com/agreementWarrantyDynamic.do
    If it does indeed show the warranty has expired, then what you need to do from here will depend on who you purchased the iPad from and when you really did purchase it. Perhaps you actually purchased it in August and are just misremembering? Check your receipt. If you confirm that you did purchase within the last calendar year, tell us exactly where you got it and we can probably offer advice.
    Regards.

  • Connection time out  what does this mean?

    connection time out  what does this mean?

    Perhaps you could try this to resolve your issue:
    Reset network settings by tapping Settings > General > Reset > Reset Network Settings.
    Note: This will reset all network settings including: previously connected Wi-Fi networks and passwords, recently used Bluetooth accessories, VPN and APN settings.

  • Pages desktop icon grayed out and slash, what's this mean?

    Pages desktop icon grayed out and slash, what's this mean?

    It means it's damaged or somehow incompatible with your current configuration. Reinstall it.
    (64111)

  • When i was waiting for an hour for itunes to grading my 2nd generation ipod touch to a 4.2.1 and it was about done, it suddenly said the network connection timed out and that made the upgrading a fail. Why does it do that? and what does it mean?

    When i was waiting for an hour for itunes to grading my 2nd generation ipod touch to a 4.2.1 and it was about done, it suddenly said the network connection timed out and that made the upgrading a fail. Why does it do that? and what does it mean?

    Error -3259 is a network timeout error, usually. This article might help:
    http://support.apple.com/kb/TS2799

  • What does this mean "We apologize for the inconvenience, but the ability to order books and prints is no longer supported in iPhoto 5. Please upgrade to a newer version of iPhoto to order these products.

    what does this mean "We apologize for the inconvenience, but the ability to order books and prints is no longer supported in iPhoto 5. Please upgrade to a newer version of iPhoto to order these products." I want to buy a photo book and that message keeps popping up.

    TD, LN - You guys make great points and I will take you at your word. Normally, I would not hesitate to update. I have a lot at stake here with a large vacation coming up with a great many new pictures anticipated. I don't know enough to understand what is meant by "verifying my library." Please give me some insight there and I will start the upgrade process tonight! Seriously, I have wanted to do this for some time, but have been scared away by reading too many situations on these forums.
    TD - you have a good sense of humor. I know all versions eventually need to be left to die away. Support is not eternal. I am sure I missed the announcement that certain versions of iPhoto would no longer offer the ability to conveniently make cards, calendars, books, etc. Like the original poster, I was surprised to learn my version did not offer that functionality only by requesting it and getting denied. Sort of frosted me at the time, as you can tell by my original reply here.
    If anyone can help me with the "verifying" question, I'll get off of here and let the original poster have his thread back! 

  • HT201272 Some songs are greyed out while others are black. What does this mean and how can I change it? I'm tired of only 2 or 3 songs from an album repeating while the others disappear off the "Up next".

    Please help....I hate iTunes to begin with. Especially the latest they have come up with. Layout drives me crazy. And now....I find maybe a couple of songs in an album as "black" and the other titles are greyed out. What does this mean? I find it very frustrating as the black titles will repeat but the others seem to just disappear off the "play next" list. How can I fix this? And no...downloading from iCloud hasn't helped any.

    This sounds like you have some unchecked tracks. These are skipped during track to track playback. The track names are slightly greyed out in the album view. You can normally see the check boxes from the Songs view or you can change the status via the rght-click context menu.
    tt2

  • My i4s wifi button is not working. when i opened the setting and then wifi the button is greyed out. then i opened general and then about. in the bar of wifi address it is written N/A. what does its mean. i have done all other things like setting general

    my i4s wifi button is not working. when i opened the setting and then wifi the button is greyed out. then i opened general and then about. in the bar of wifi address it is written N/A. what does its mean. i have done all other things like setting >general<reset<reset network setting. but all in vain. tell me the solution

    restore your phone as new through itunes. if the issue persists after a factory restore via itunes, it means you've got a hardware issue and the phone needs to be repaired

  • TS1398 the wifi bar is greyed out what does that mean?

    The wifi bar is greyed out what does that mean?

    If that doesn't work:
    1.  Backup to iTunes (NOT iCloud)—be sure to backup Apps
    2.  Delete all content
    3.  Set up as new—don't restore from backup
    4. Restore from iTUNES (NOT icloud) backup
    5.  Then re-add your content.

  • HT3412 Want to order books but received the following message, "your book appears to have unedited text which will not print in your book."  What does that mean?

    Please help.  Want to order completed book but received the following message, "your book appears to have unedited text which will not be printed in your book."  What does that mean?  Why did the program let me use text that will not print?

    Go thru every page in the book and look for any text box.  Unused text boxes will have somegthing like this in them:
    or this:
    Just put a space in those text boxes where you didn't put text previously.  Check the inside flaps of the book jacket also.

  • I am getting an Narration error that I can't record because one of the record-enabled tracks is locked in the timeline. What does this mean and how do I get out of it??

    I am getting an Narration error that I can't record because one of the record-enabled tracks is locked in the timeline. What does this mean and how do I get out of it??

    JohnL23
    Thanks for the update.
    There are several Adobe Premiere Elements Forum threads about situation such as the one that you have encountered. Typically they are the results of some heavy activity in the narration track.  Some have found success in maneuvers between the Expert and Quick workspaces in versions 11 and 12 or Timeline and Sceneline workspaces in versions earlier than 11. That is why I mentioned that type of factor in a prior post in your thread.
    If that is not working, then we are forced into the new project where the problems in the current project are not presenting.
    I will do a search for the threads that I am recalling about your type of issue. But, right now all roads seem to head to the new project. But I would ask "Can you salvage this project by creating your narration clips in Audacity or a new Premiere Elements project and import them into this project, putting the clips on one of the numbered audio tracks?"
    If the problem should reappear in the new project, please let us know including the details of what was going on immediate before the problem surfaced.
    Thanks.
    ATR

Maybe you are looking for

  • Need to do a clean install on my new iMac

    I have a new iMac and after migrating everything from my old one, I am getting some strange problems.  Things like not being able to shut down without doing a forced shut down and some other small things here and there that Apple have not been able t

  • Every time i use facebook.. its asking permision every time i change the page or click any link in the the page.. can u help me to solve this???

    i have checked all the option in the option bar in the firefox.. but nothing could help me solving this problem... every time i click home,or try to visit someones profile, or any link in my page its asking for a permision.. saying.. u like to leave

  • Itunes installation file wont run

    I have successfully downloaded itunes801Setup.exe. When I run it it gives the usual XP warning stating publisher not verified. When I click run nothing happens. I have also downloaded the quicktime installer file with identical results. Everything el

  • Next component to get focus?

    Hey Guys, If i had a panel with buttons and other components and if the focus is on one of the buttons, is it possible to have java return what the next component to get the focus is? I know there's a getNextFocusableComponent, but i'd rather use som

  • Second BW data load job waits for first to complete.

    Hi all, Iam manually loading data into my BW system , i have observed that if i try to load two data source together the system wait fror one to complete then only it will trigger the secnond load. eg if i run 2lis_11_vahdr and 2lis_13_Vdhdr together