• Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

0xc0040017 FWX_E_TCP_NOT_SYN

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> Logging and Reporting >> 0xc0040017 FWX_E_TCP_NOT_SYN Page: [1]
Message << Older Topic   Newer Topic >>
0xc0040017 FWX_E_TCP_NOT_SYN - 16.Dec.2004 8:05:00 PM   


Posts: 38
Joined: 18.Feb.2004
From: Pennsauken NJ
Status: offline
Hi all,

This message in my logs has been irritating me for a while because I don't know if I should do anything about it. I spent some time analyzing smtp transactions that got the connection denied log entry with this reason code. Using both a hardware sniffer and Microsoft's Network Monitor , this is what I found.

First of all, the message time can, and often is, well after any event associated with the session or transaction. Some mail transactions completed in milliseconds while this message was written sveeral seconds after the last segment had been processed. The hardware trace verified that the MIcrosoft Network Monitor was correct and there was no traffic when the log was written.

What this message seems to indicate is that the reset bit (RST) occurs in a segment without an accompanying ACK. Sometimes these are found after the FIN-FIN segments indicating end of session, sometimes they occur before the transaction handshake, and sometime the mail server sending them seems to wqant to start over and does it by sending segments with RST set.

Since I can't correlate the time I can't be 100% on this, but sesions with 11 reset segments eventually resulted in 11 logged "denied connections." Sessions without any solo RST flags did not have any issue.

In no case was any mail lost so it seems to be mail servers that don't do things totally by the books but they do follow RFC 793 which allows, for example, sessions to be ended by reset flags.

I am going to ignore them unless any of you suggest further analysis.

Post #: 1
RE: 0xc0040017 FWX_E_TCP_NOT_SYN - 18.Dec.2004 6:26:00 PM   


Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Paul,

Are these connections exceeding the connection limit set for the machine?


(in reply to pwaldeier)
Post #: 2

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> Logging and Reporting >> 0xc0040017 FWX_E_TCP_NOT_SYN Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts