Re: [fw-wiz] Source of T/TCP traffic
From: Volker Tanger (volker.tanger_at_discon.de)
Date: 09/09/03
- Previous message: Dave Killion: "RE: [fw-wiz] Source of T/TCP traffic"
- In reply to: Knut Bjornstad: "[fw-wiz] Source of T/TCP traffic"
- Next in thread: Knut Bjornstad: "Re: [fw-wiz] Source of T/TCP traffic"
- Reply: Knut Bjornstad: "Re: [fw-wiz] Source of T/TCP traffic"
- Reply: Knut Bjornstad: "Re: [fw-wiz] Source of T/TCP traffic"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: Knut Bjornstad <kbjo@interpost.no> Date: Tue, 9 Sep 2003 14:22:58 +0200
Greetings!
On Tue, 9 Sep 2003 Knut Bjornstad <kbjo@interpost.no> wrote:
> Our IDS are seeing a lot of peculiar T/TCP traffic - the alerts on
> this is no problem in itself - I can easily disable them. But when I
> try to analyze the traffic, it seems like ordinary web traffic from
> various MS IE sources.
Do you see T/TCP, TAO or the braindead MS-IE/IIS speedup hack? Usually
newer IE try to send the HTTP request already in the SYN packet (or was
it first sending an ACK packet with the request?) ignoring the usual
need for a SYN - SYN/ACK - ACK handshake for a proper TCP connection.
While the IIS answers directly other servers respond with a RST, upon
which the IIS starts anew with the standard 3-way handshake. This way
a MS-IE/MS-IIS pair has a small speed advantage over standard clients
or servers. It's called improving industry standards, I fear.
If this is the traffic you see, you can safely ignore it (as MS-IE
does).
HTH
Volker Tanger
_______________________________________________
firewall-wizards mailing list
firewall-wizards@honor.icsalabs.com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
- Previous message: Dave Killion: "RE: [fw-wiz] Source of T/TCP traffic"
- In reply to: Knut Bjornstad: "[fw-wiz] Source of T/TCP traffic"
- Next in thread: Knut Bjornstad: "Re: [fw-wiz] Source of T/TCP traffic"
- Reply: Knut Bjornstad: "Re: [fw-wiz] Source of T/TCP traffic"
- Reply: Knut Bjornstad: "Re: [fw-wiz] Source of T/TCP traffic"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|