This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG-> TCP Packets with invalid flag combination

Hello Folks,

 

well i got a problem with my Synology Storage. Lets get the information down.

 

My Computer (192.168.0.20, LAN Zone) wants to watch a video on my Synology (192.168.10.10, DMZ). But my VLC Player can't play the file. In the logs i see the following: 

messageid="01001" log_type="Firewall" log_component="Invalid Traffic" log_subtype="Denied" status="Deny" con_duration="0" fw_rule_id="0" policy_type="0" user="" user_group="" web_policy_id="0" ips_policy_id="0" appfilter_policy_id="0" app_name="" app_risk="0" app_technology="" app_category="" in_interface="" out_interface="" src_mac="" src_ip="192.168.0.20" src_country="" dst_ip="192.168.10.10" dst_country="" protocol="TCP" src_port="60168" dst_port="17035" packets_sent="0" packets_received="0" bytes_sent="0" bytes_received="0" src_trans_ip="" src_trans_port="0" dst_trans_ip="" dst_trans_port="0" src_zone_type="" src_zone="" dst_zone_type="" dst_zone="" con_direction="" con_id="" virt_con_id="" hb_status="No Heartbeat" message="TCP Packets with invalid flag combination." appresolvedby="Signature"

 

I really dont know what is happening. My Rule:

 

What can i do to get my connection working?

The Synology got only 1 LAN-Connection. Edit: When i will place the Synology into the LAN (192.168.0.10) all is working fine. But that is not my intention. 

 

Thanks guys! Kind regards,

Chris



This thread was automatically locked due to age.
  • Hi,

    basically that error shows your rule is being ignored.

    I hope that isn't your rule because it is incomplete? I would check your destination configuration.

    I suspect rather than a firewall rule you need a routing rule.

    Ian

    XGS118 - v21.5.0

    XG115 converted to software licence v21.5.0

    If a post solves your question please use the 'Verify Answer' button.

    • Hey Ian,

       

      well now i see what you mean, no FW-rule is applied (fw_rule=0).. Thats bad. The FW Rule works - somtimes, because i can see traffic to my server or from it when i copy and paste the files. ... the object got only one ip-address on itself, the ip i mentioned earlier. 

      How can i go deeper into this? :)

      • Hey guys,

         

        just to resolve this, my mainboard got 3 NIC's. 1x 10Gbit and 2x Intel Lan 1Gbit. It was the 10Gbit card, i think the driver is not ready yet to work with a firewall lol. 

         

        Okay i will keep an i on this one. 

         

        Thanks for Help Ian