Description

This article provides information on the behavior of non-SYN packets for non-existing sessions when both tcp-rst and no-syn-check are configured.

Solution

When the "no-syn-check" option is enabled under security flow and TCP-RST is configured for the source security zone, the "no-syn-check" setting takes priority. As a result, even with TCP-RST configured, if the first packet is not a SYN, the SRX will allow the packet through without checking the SYN flag, thereby bypassing the TCP-RST configuration.

Modification History

2024-08-10 : Article Created