Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

What is Removed the urgent flag and pointer in TCP header? What should I do about it?

Hi, 

I am very new to firewalls in general. 

For the last couple of days, I have been getting "Removed the urgent flag and pointer in TCP header" notifications on the network attacks

It targets our web server on DMZ. 

What does this mean? Is there something I need to do? what would be my due diligence and best practices? 

Thank you for your time. 

  



Edited TAGs
[edited by: Erick Jan at 3:45 AM (GMT -8) on 21 Feb 2025]
  • Hi,

    Thank you for reaching out to Sophos Community.

    The log entry "Removed the urgent flag and pointer in TCP header" is generated by the TCP normalization feature of your Sophos Firewall. It occurs when the firewall detects and modifies TCP packets with the URG (urgent) flag set, which can be used in certain types of attacks (e.g., Urgent Pointer exploits or TCP stream injection). It can also occur due to non-malicious behavior, such as legacy or misconfigured applications using deprecated TCP urgent flags.

    Potential Threats:

    • Possible TCP Urgent Pointer exploits or reconnaissance attempts.
    • It could be false positives from legacy applications or misconfiguration

    Related Settings:

    • DPI Engine: TCP normalization policy.
    • IPS Rules: TCP exploit detection.
    • Application Filter: Possible flag inspection.

    Recommended Actions:

    • Review IPS Logs: Identify any triggered rules.
    • Packet Capture: Analyze traffic patterns.
    • Update IPS Patterns: Ensure rules are up-to-date.
    • Adjust TCP Normalization: Modify policies if traffic is legitimate.

    Erick Jan
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.