<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5506-X False SYN Attack in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5506-x-false-syn-attack/m-p/4046651#M1067819</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;If the connection is successful, it should not show up as "SYN Attack"; if you want to exclude a host from being shunned, use the "threat-detection scanning-threat shun except". For more reference look at this example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113685-asa-threat-detection.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113685-asa-threat-detection.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Mar 2020 14:58:35 GMT</pubDate>
    <dc:creator>Cristian Matei</dc:creator>
    <dc:date>2020-03-16T14:58:35Z</dc:date>
    <item>
      <title>ASA 5506-X False SYN Attack</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-false-syn-attack/m-p/4046260#M1067801</link>
      <description>&lt;P&gt;ASA 5506-X running as ASA only 9.13.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Exchange server (192.168.1.5) is unable to connect to the 192.124.249.xxx addresses because of a perceived SYN Attack&lt;/P&gt;&lt;P&gt;This is preventing my SSL certificates from working properly&lt;/P&gt;&lt;P&gt;Is there any way to whitelist these external IP addresses ? They are valid and part of GoDaddy's CRL list&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Her are the stats from : show threat-detection statistics top&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;Rank&amp;gt; &amp;lt;Server IP:Port&amp;gt; &amp;lt;Interface&amp;gt; &amp;lt;Ave Rate&amp;gt; &amp;lt;Cur Rate&amp;gt; &amp;lt;Total&amp;gt; &amp;lt;Source IP (Last Attack Time)&amp;gt;&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;1 123.123.123.101:443 outside 0 0 19 216.211.109.235 (0 secs ago)&lt;BR /&gt;2 192.124.249.36:80 inside_1 0 0 8 192.168.1.5 (3 mins ago)&lt;BR /&gt;3 192.124.249.41:80 inside_1 0 0 8 192.168.1.5 (2 mins ago)&lt;BR /&gt;4 192.124.249.22:80 inside_1 0 0 5 192.168.1.5 (4 mins ago)&lt;BR /&gt;5 192.124.249.23:80 inside_1 0 0 4 192.168.1.5 (3 mins ago)&lt;BR /&gt;6 192.124.249.24:80 inside_1 0 0 4 192.168.1.5 (3 mins ago)&lt;BR /&gt;7 192.124.249.31:80 inside_1 0 0 4 192.168.1.5 (3 mins ago)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 01:18:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-false-syn-attack/m-p/4046260#M1067801</guid>
      <dc:creator>Steve Babcock</dc:creator>
      <dc:date>2020-03-16T01:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506-X False SYN Attack</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-false-syn-attack/m-p/4046651#M1067819</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;If the connection is successful, it should not show up as "SYN Attack"; if you want to exclude a host from being shunned, use the "threat-detection scanning-threat shun except". For more reference look at this example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113685-asa-threat-detection.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113685-asa-threat-detection.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 14:58:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-false-syn-attack/m-p/4046651#M1067819</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-16T14:58:35Z</dc:date>
    </item>
  </channel>
</rss>

