Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Teardrop false positive

Status
Not open for further replies.
Apr 17, 2003
18
GB
I've got a VPN configured as follows


Nortel VPN Device --- Internet -- PIX -- Nortel VPN

Sadly, the PIX is dropping packets between Nortel boxes believing its a teardrop attack(I believe its because packet size is 1497, because the IPSec stuff is fragmenting the packets). I've disabled the relivant IDS signatures but problems, packet drops and syslogs errors persist.

Any thoughts?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top