<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA5506-x SHowing False SYN Attack in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5506-x-showing-false-syn-attack/m-p/3348923#M1064245</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are referring to 'top usage status', that setting is controlled by threat detection feature which can be played around by below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;configuration &amp;gt; firewall &amp;gt; threat detection&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa97/asdm77/general/asdm-77-general-config/intro-asdm.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa97/asdm77/general/asdm-77-general-config/intro-asdm.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;</description>
    <pubDate>Thu, 15 Mar 2018 04:40:08 GMT</pubDate>
    <dc:creator>Ajay Saini</dc:creator>
    <dc:date>2018-03-15T04:40:08Z</dc:date>
    <item>
      <title>ASA5506-x SHowing False SYN Attack</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-x-showing-false-syn-attack/m-p/3324404#M1064241</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This could be due to pure ignorance on my part, but I noticed odd behavior on one of the ASA's I manage.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There were a couple clients&amp;nbsp;showing as the source IP for a SYN Attack. Of course, I jumped to malware and scanned the heck out of one of the clients. In the meantime, I arrived onsite and jumped on my machine. While montoring, my device was flagged as a SYN Attack.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After doing a little more digging, it looks like some legit traffic (Microsoft, Logmein, etc.) is being flagged. Is this simply because of the breakdown of the TCP handshake?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:16:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-x-showing-false-syn-attack/m-p/3324404#M1064241</guid>
      <dc:creator>andysmithor</dc:creator>
      <dc:date>2020-02-21T15:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506-x SHowing False SYN Attack</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-x-showing-false-syn-attack/m-p/3348213#M1064242</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It could be a false positive, depends on the feature which triggered these logs - was it threat-detection or MPF policy. If you are sure that its a false positive, you can tweak the policy to increase the values which are a criteria for syn attack on ASA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where did you find the false syn attack , was it syslog or some other tool?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 08:51:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-x-showing-false-syn-attack/m-p/3348213#M1064242</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-03-14T08:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506-x SHowing False SYN Attack</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-x-showing-false-syn-attack/m-p/3348333#M1064243</link>
      <description>&lt;P&gt;Where exactly can IPS TCP Syn threshold can be changed?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you share maybe the GUI menu or CLI command if the case?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 12:09:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-x-showing-false-syn-attack/m-p/3348333#M1064243</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-03-14T12:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506-x SHowing False SYN Attack</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-x-showing-false-syn-attack/m-p/3348578#M1064244</link>
      <description>&lt;P&gt;It's a view segment&amp;nbsp;in the ADMIN GUI for the ASA. I check it out occasionally and they always seem to point to legit IP's. I think it's just dropped packets triggering the alert. No issues with the network because of this, just looking into it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the reply.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 16:01:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-x-showing-false-syn-attack/m-p/3348578#M1064244</guid>
      <dc:creator>andysmithor</dc:creator>
      <dc:date>2018-03-14T16:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506-x SHowing False SYN Attack</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-x-showing-false-syn-attack/m-p/3348923#M1064245</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are referring to 'top usage status', that setting is controlled by threat detection feature which can be played around by below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;configuration &amp;gt; firewall &amp;gt; threat detection&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa97/asdm77/general/asdm-77-general-config/intro-asdm.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa97/asdm77/general/asdm-77-general-config/intro-asdm.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 04:40:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-x-showing-false-syn-attack/m-p/3348923#M1064245</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-03-15T04:40:08Z</dc:date>
    </item>
  </channel>
</rss>

