TCP Resets and Switches
One of the actions that your sensor can take in response to detecting a TCP-based attack is to reset the TCP connection. The sensor resets the TCP connection by sending out TCP packets with the RST flag set to both the source and destination of the TCP connection via its monitoring interface.
Not all switches allow a port that is configured as the SPAN destination port to receive incoming traffic. Since the sensor's monitoring interface is usually a SPAN port on a Cisco switch, this presents a problem. If the switch does not enable the SPAN destination port to receive incoming traffic, the TCP RST packets will not be accepted, thus preventing the sensor from resetting the TCP connection. Therefore, if you are using a SPAN port to capture your network traffic and plan to use the TCP reset capability, you need to verify that your switch supports the capability to receive incoming traffic on the SPAN destination port.
Continue reading here: The monitor session Command
Was this article helpful?