<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Protecting against DDOS attacks in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/protecting-against-ddos-attacks/m-p/3944440#M547770</link>
    <description>This isn’t the right forum for routing questions, please move to routing platforms&lt;BR /&gt;</description>
    <pubDate>Mon, 21 Oct 2019 10:33:38 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2019-10-21T10:33:38Z</dc:date>
    <item>
      <title>Protecting against DDOS attacks</title>
      <link>https://community.cisco.com/t5/network-access-control/protecting-against-ddos-attacks/m-p/3939285#M547769</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a Cisco 2901 router configured to allow access to a DVR device using NAT and ACLs from the Internet. I can't lock down the ACLs to a source IP due the customer's DRV app needing to access the DVR from anywhere out on the Internet. I see port scans happening from various suspicious locations scanning the routers IP, which is hidden, for port 7000. They can't gain access to the DRV device but is there a way to deny port scans from getting to port 7000? Is there something to deny based on scan frequency or possibly seeing no connection establishment to DVR device and then deny source IP?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;BR /&gt;description Internet Outside GigabitEthernet0/0&lt;BR /&gt;ip address x.x.x.x 255.255.255.252&lt;BR /&gt;ip access-group 190 in&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;BR /&gt;description DVR Device&lt;BR /&gt;ip address 192.168.4.1 255.255.255.0&lt;BR /&gt;ip access-group 104 in&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 192.168.4.2 35000 interface GigabitEthernet0/0 7000&lt;/P&gt;&lt;P&gt;ip nat inside source route-map NAT_MAP_1 interface GigabitEthernet0/0 overload&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;oute-map NAT_MAP_1 permit 1&lt;BR /&gt;match ip address 100&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;access-list 100 permit ip 192.168.4.0 0.0.0.255 any&lt;BR /&gt;access-list 100 deny ip any any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list 104 remark ------ DVR Device IN Rules ------&lt;BR /&gt;access-list 104 permit tcp host 192.168.4.2 any eq www&lt;BR /&gt;access-list 104 permit udp host 192.168.4.2 any eq domain&lt;BR /&gt;access-list 104 permit tcp host 192.168.4.2 eq 35000 any&lt;BR /&gt;access-list 104 deny ip any any log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list 190 permit tcp any any eq 7000 log&lt;/P&gt;&lt;P&gt;access-list 190 deny ip any any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GW&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:10:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/protecting-against-ddos-attacks/m-p/3939285#M547769</guid>
      <dc:creator>theitmedic</dc:creator>
      <dc:date>2020-02-21T19:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: Protecting against DDOS attacks</title>
      <link>https://community.cisco.com/t5/network-access-control/protecting-against-ddos-attacks/m-p/3944440#M547770</link>
      <description>This isn’t the right forum for routing questions, please move to routing platforms&lt;BR /&gt;</description>
      <pubDate>Mon, 21 Oct 2019 10:33:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/protecting-against-ddos-attacks/m-p/3944440#M547770</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-10-21T10:33:38Z</dc:date>
    </item>
  </channel>
</rss>

