Re: 0xc0040017 FWX E TCP NOT SYN PACKET DROPPED

From: Yossi Attas [MSFT] (yossia_at_online.microsoft.com)
Date: 09/05/04


Date: Sun, 5 Sep 2004 16:23:02 +0300

Hi Lex,
The error code that you describe usually appears when either side of the
connection end points sends a packet (to the other side) after the
connection has already been closed (from ISA's pov).
To drill down into this issue and link it to the file server connectivity
issue i would suggest that you do the following:
1. Create an ISA log query to show you all the packets that were dropped
with this result code (
0xc0040017 FWX E TCP NOT SYN PACKET DROPPED).
2. Choose one packet and construct an ISA log query to show you the entire
connection history for this packet. You can do it by creating a log query
based on client ip, source port and time.
3. If the issue is what i think it is, you will see that ISA dropped the
packet (0xc0040017) after the connection has already been terminated.
4. The interesting thing would then be to understand whether the connection
was terminated gracefully or abortively.

Can you please provide the above details so we can decide how to continue?

Thanks
Yossi Attas [MSFT]

"penrose.l" <anonymous@discussions.microsoft.com> wrote in message
news:2c8f01c48eb1$add48c40$a501280a@phx.gbl...
> btw : this is not a hacker attempt or anything.
> It's our own clients that copy files from their computer
> to a server , and if they copy large files of around 10 or
> 20 megabytes or more , they will fail during copy ( every
> time at a different % done ).
>
> LexP



Relevant Pages

  • Re: peer to peer messaging
    ... attempts to open a connection to port 80 of the server at that IP address. ... For example a packet from my machine might have source IP ... Packets from the sever to my laptop would have those reversed. ...
    (comp.lang.java.programmer)
  • Re: IPFW Dynamic Rules
    ... > So if the dynamic rule has the same behaviour as the origination ... > rule on the same port with the same protocol, ... If client sends UDP query to DNS on your machine, you get the packet: ... is deleted after connection is inactive for some time. ...
    (FreeBSD-Security)
  • [NEWS] Cisco PIX TCP Connection DoS
    ... Get your security news from a reliable source. ... By crafting a special TCP packet and sending it to a vulnerable Cisco PIX, ... embryonic connection open until the embryonic connection timeout which is ...
    (Securiteam)
  • Re: Nmap questions concering my router
    ... that may have to be fetched) is downloaded as one connection. ... >> all addresses (and may listen using just one interface to receive all ... sends packets to the correct protocol driver ... wire to an IP packet, and hands this to the IP driver which strips off ...
    (comp.security.firewalls)
  • Re: Port "triggering"
    ... The reason you should specify the -d above is if you have two internal nets ... If you are connecting to some outside server your connection will never make ... Again, the rule you had takes every single packet going to port 3783, no ... At the end of each chain I do a: ...
    (comp.os.linux.security)