|
The malformed SYN packets are sent through the PIX firewall, and are dropped by the host on the inside network without issuing a RST. The PIX maintains an half open state through for either 120 seconds or 30 seconds depending on your PIX software version. The embryonic timeout value does not allow further traffic to pass until the inside host responds back to the originator, or the timeout value has expired. Since the inside host dropped the malformed packet and did not issue a RST, the Pix will wait for the embryonic timeout value to expire before allowing traffic to pass through that connection once again.
|