2.38. IP_FLAG

These log messages refer to the IP_FLAG (Events concerning the IP header flags) category.

2.38.1. ttl_low (ID: 01600001)

Default Severity
WARNING
Log Message
Received packet with too low TTL of <ttl>. Min TTL is <ttlmin>. Ignoring
Explanation
The received packet has a TTL (Time-To-Live) field which is too low. Ignoring and forwarding packet anyway.
Firewall Action
ignore
Recommended Action
None
Revision
1
Parameters
ttl
ttlmin
Context Parameters
Rule Name
Packet Buffer

2.38.2. ip_rsv_flag_set (ID: 01600002)

Default Severity
NOTICE
Log Message
The IP Reserved Flag was set. Ignoring
Explanation
The received packet has the IP Reserved Flag set. This is ignored.
Firewall Action
ignore
Recommended Action
None
Revision
1
Context Parameters
Rule Name
Packet Buffer

2.38.3. ip_rsv_flag_set (ID: 01600003)

Default Severity
WARNING
Log Message
The IP Reserved Flag was set, stripping
Explanation
The received packet has the IP Reserved Flag set. Removing it.
Firewall Action
strip_flag
Recommended Action
None
Revision
1
Context Parameters
Rule Name
Packet Buffer

2.38.4. hop_limit_low (ID: 01600004)

Default Severity
WARNING
Log Message
Received packet with too low HopLimit of <hoplimit>. Min HopLimit is <hoplimitmin>. Ignoring
Explanation
The received packet has a HopLimit field which is too low. Ignoring and forwarding packet anyway.
Firewall Action
ignore
Recommended Action
None
Revision
1
Parameters
hoplimit
hoplimitmin
Context Parameters
Rule Name
Packet Buffer