There are often erroneous logs generated by the LATE DROP feature.
These occur for TCP packets where they are no valid NEW packets, I presume from script kiddies.
Note the mix of ACK FIN, ACK SYN and ACK RST flags in the packets which makes them invalid "NEW" connections so are not processed by a cross-zone block (eg, x_NET_ME):
There are often erroneous logs generated by the LATE DROP feature.
These occur for TCP packets where they are no valid NEW packets, I presume from script kiddies.
Note the mix of
ACK FIN
,ACK SYN
andACK RST
flags in the packets which makes them invalid "NEW" connections so are not processed by a cross-zone block (eg, x_NET_ME):