Flex H configure 'source port is zero DROP' logging

best_heygman
best_heygman Posts: 12  Freshman Member
First Comment Friend Collector

Hello, I have an USG Flex H 50 and I get a huge number of alert messages of the type:
abnormal tcp traffic detected, source port is zero DROP

I have not found any way to disable these logs and they are drowning the important stuff, as you can see on the screenshot. The firewall is already blocking this traffic and that's all that matters to me. No reason for me to see it, as it is expected behaviour that the internet throws the weirdest stuff at everything that is directly connected, therefore I would like to have the option to disable these logs. Doesn't have to be the default, just optional.

I would suggest making this configurable in System → Advanced → Additional Features , where already the log level of stuff like "Drop Invalid TCP Flags Pkt" can be configured.

Bildschirmfoto vom 2025-04-20 19-11-57.png
2
2 votes

In Progress · Last Updated

The "abnormal TCP traffic detected" log will be set to debug level to prevent it from appearing too frequently in the default logs.

Comments

  • Zyxel_James
    Zyxel_James Posts: 683  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 100 Answers

    Thanks for your sharing, we will enhance it in next FCS by adjusting this log to debug level, so that this kind of log will not appear by default.

  • best_heygman
    best_heygman Posts: 12  Freshman Member
    First Comment Friend Collector

    Thank you @Zyxel_James, these are great news 👍
    Ok, now I don't know how to mark this idea as solved…