<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Mike, Thanks very much for in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/synflood-mitigation/m-p/2438576#M267378</link>
    <description>&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Hi Mike,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Thanks very much for taking the time to reply. &amp;nbsp;I've been studying the ASA documentation and CLI reference, so i've got a good idea now and your reply has confirmed my thoughts.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;I've ordered an ASA 5550 from Ebay - at just over £1100.00 it offered the best £ per session/throughput ratio. Obviously it's last generation,&amp;nbsp;but i i don't believe this will be an issue for us.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Once i have this one installed and running i'll probably end up getting another for HA, especially being used equipment, considering it's sitting directly on my entire companies uplink!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;I plan to deploy this in transparent mode, we use on server software firewalls already for specific port blocking, which will stay in place as every customers requirement is different - the ASA will be used for DOS deflection and anything else it can do to ensure only 'clean' packets enter our network. I don't need it to go into the application level i don't believe. Which brings me onto my next question if i may? &amp;nbsp;What other features of the ASA are useful in this situation? &amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px; font-family: arial, helvetica, sans-serif; color: rgb(0, 0, 0); line-height: normal;"&gt;I've picked this list from the connection section of the configuration guide, i think all of these will be useful to us:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/firewall/asa_91_firewall_config/conns_connlimits.html#pgfId-1080752" style="color: rgb(51, 102, 204);"&gt;Dead Connection Detection (DCD)&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/firewall/asa_91_firewall_config/conns_connlimits.html#pgfId-1080757" style="color: rgb(51, 102, 204);"&gt;TCP Sequence Randomization&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/firewall/asa_91_firewall_config/conns_connlimits.html#pgfId-1090664" style="color: rgb(51, 102, 204);"&gt;TCP Normalization&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/firewall/asa_91_firewall_config/conns_connlimits.html#pgfId-1089825" style="color: rgb(51, 102, 204);"&gt;TCP State Bypass&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&lt;SPAN style="font-size: 14px; font-family: arial, helvetica, sans-serif;"&gt;But then i also wonder about some of the other features the ASA has. &amp;nbsp;Can you or anyone offer advice on what are useful features that i should focus on setting up for deploying the ASA at the network edge?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Thanks again,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Elliot&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Apr 2014 18:12:37 GMT</pubDate>
    <dc:creator>elliotpea</dc:creator>
    <dc:date>2014-04-21T18:12:37Z</dc:date>
    <item>
      <title>SynFlood Mitigation</title>
      <link>https://community.cisco.com/t5/network-security/synflood-mitigation/m-p/2438574#M267373</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I run a small hosting company with a round 100 servers. &amp;nbsp;We have a 1Gbps Uplink, but only utilise around 120Mbps outbound.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recently we've had the pleasure of a Spoofed SynFlood attack to one of our hosts. &amp;nbsp;This hasn't cause any network wide issues, just problems to that specific host (Linux based). &amp;nbsp;In 48 hours i've had a steep leaning curve on what a SynFlood attack actually is and the options to mitigate it. &amp;nbsp;So far any attempt to OS level mitigations have proved ineffective. Such as enabling syn cookies, increasing the backlog size, and other kernel tuning.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So i'm here looking for advice for an ASA which would be suitable for my requirements which would help protect the hosts behind it from such an attack. From what i understand this is done by the ASA proxying the syn requests, and only passing completed handshakes through to the hosts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're only a small company, so budget is a problem - i have been looking on ebay at two 5520's in HA. &amp;nbsp;However, i'm concerned about the number of concurrent connections. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my testing, i've managed to Synflood at test server with 300,000 open states. &amp;nbsp;This was a simple case of a Linux virtual machine attacking another one over a WAN connection - approx 10Mbps of traffic, 8K PPS and 300,000 concurrent states.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My testing was done with a freely available synflood spoof script from github (it scares me how easily this is to do).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you possibly advice on what cisco product i should be looking at, and if i'm going in the right direction?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Elliot&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:06:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/synflood-mitigation/m-p/2438574#M267373</guid>
      <dc:creator>elliotpea</dc:creator>
      <dc:date>2019-03-12T04:06:28Z</dc:date>
    </item>
    <item>
      <title>Hi,The technology you are</title>
      <link>https://community.cisco.com/t5/network-security/synflood-mitigation/m-p/2438575#M267374</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The technology you are looking at using is TCP intercept which is used to protect against a large number of incomplete TCP sessions (what you have), the 'threshold' for this should be set to a value which is below the capabilites of the server you are trying to protect.&lt;/P&gt;&lt;P&gt;On the firewall, this is configured using a service policy; you configure:&lt;/P&gt;&lt;P&gt;- maximum concurrent connections&lt;/P&gt;&lt;P&gt;- max embryonic connections&lt;/P&gt;&lt;P&gt;- max per client connections&lt;/P&gt;&lt;P&gt;and you configure various timeout values to specify the behaviour of the firewall when embryonic connections start to occur.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So - you need a firewall which has capabilities above and beyond the server you are trying to protect, If you are saying you need to be able to defend against is 300,000 concurrent sessions - don't forget you will have other sessions passing through the firewall at the same time, so it would be better to get something large enough to handle all your traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use 5545X firewalls which I think can handle 750,000 concurrent sessions. #&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The data sheets for older ASAs can be found here&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/product_data_sheet0900aecd802930c5.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and for the next generation can be found here&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/products/collateral/routers/800-series-routers/data-sheet-c78-729807.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and a good explanation of TCP intercept is here&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/firewall/asa_91_firewall_config/conns_connlimits.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best wishes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Sun, 20 Apr 2014 20:31:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/synflood-mitigation/m-p/2438575#M267374</guid>
      <dc:creator>luckymike33</dc:creator>
      <dc:date>2014-04-20T20:31:12Z</dc:date>
    </item>
    <item>
      <title>Hi Mike, Thanks very much for</title>
      <link>https://community.cisco.com/t5/network-security/synflood-mitigation/m-p/2438576#M267378</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Hi Mike,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Thanks very much for taking the time to reply. &amp;nbsp;I've been studying the ASA documentation and CLI reference, so i've got a good idea now and your reply has confirmed my thoughts.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;I've ordered an ASA 5550 from Ebay - at just over £1100.00 it offered the best £ per session/throughput ratio. Obviously it's last generation,&amp;nbsp;but i i don't believe this will be an issue for us.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Once i have this one installed and running i'll probably end up getting another for HA, especially being used equipment, considering it's sitting directly on my entire companies uplink!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;I plan to deploy this in transparent mode, we use on server software firewalls already for specific port blocking, which will stay in place as every customers requirement is different - the ASA will be used for DOS deflection and anything else it can do to ensure only 'clean' packets enter our network. I don't need it to go into the application level i don't believe. Which brings me onto my next question if i may? &amp;nbsp;What other features of the ASA are useful in this situation? &amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px; font-family: arial, helvetica, sans-serif; color: rgb(0, 0, 0); line-height: normal;"&gt;I've picked this list from the connection section of the configuration guide, i think all of these will be useful to us:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/firewall/asa_91_firewall_config/conns_connlimits.html#pgfId-1080752" style="color: rgb(51, 102, 204);"&gt;Dead Connection Detection (DCD)&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/firewall/asa_91_firewall_config/conns_connlimits.html#pgfId-1080757" style="color: rgb(51, 102, 204);"&gt;TCP Sequence Randomization&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/firewall/asa_91_firewall_config/conns_connlimits.html#pgfId-1090664" style="color: rgb(51, 102, 204);"&gt;TCP Normalization&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/firewall/asa_91_firewall_config/conns_connlimits.html#pgfId-1089825" style="color: rgb(51, 102, 204);"&gt;TCP State Bypass&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&lt;SPAN style="font-size: 14px; font-family: arial, helvetica, sans-serif;"&gt;But then i also wonder about some of the other features the ASA has. &amp;nbsp;Can you or anyone offer advice on what are useful features that i should focus on setting up for deploying the ASA at the network edge?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Thanks again,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Elliot&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MiniTOC3" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 0px; margin-left: 2em; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2014 18:12:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/synflood-mitigation/m-p/2438576#M267378</guid>
      <dc:creator>elliotpea</dc:creator>
      <dc:date>2014-04-21T18:12:37Z</dc:date>
    </item>
    <item>
      <title>Hi Elliot, That's not a bad</title>
      <link>https://community.cisco.com/t5/network-security/synflood-mitigation/m-p/2438577#M267382</link>
      <description>&lt;P&gt;Hi Elliot,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's not a bad start - although it can be very very hard to successfully defend against this kind of attack (mainly due to the distributed nature of them), But other things you can do are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Configure the botnet traffic filter - this is something like a reputation based filter that filters against a known blacklist.&lt;/P&gt;&lt;P&gt;2. configure threat detection - although this is more of a monitoring tool, with some analysis it can provide valid info, on most vulnerable servers etc&lt;/P&gt;&lt;P&gt;3. Filter spoofed ip addresses, i.e. private ip addressing etc&lt;/P&gt;&lt;P&gt;4. consider increasing your bandwidth, increasing server capacity (can be expensive and futile though)&lt;/P&gt;&lt;P&gt;5. consider employing the services of a 3rd party ddos prevention - i.e. at &amp;amp; t.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These things can be very hard to defend against, but probably the best thing you can do is to tune your ASA TCP connection settings until you are happy that you are not throwing away genuine traffic whilst resetting the embryonic half open sessions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best of luck&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2014 22:43:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/synflood-mitigation/m-p/2438577#M267382</guid>
      <dc:creator>luckymike33</dc:creator>
      <dc:date>2014-04-21T22:43:36Z</dc:date>
    </item>
  </channel>
</rss>

