<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5585 - Can I shun syn attacks as well as scanning threats? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5585-can-i-shun-syn-attacks-as-well-as-scanning-threats/m-p/2464230#M268270</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I see that with threat-detection enabled and configured, I can use the "threat-detection scanning-threat shun duration [time in seconds]" to shun IPs that are scanning for open ports.&lt;/P&gt;&lt;P&gt;Is there a way to shun syn-attacks that I have a threshold set for?&lt;/P&gt;&lt;P&gt;For example I can configure this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;threat-detection rate syn-attack rate-interval 600 average-rate 30 burst-rate 45&lt;/P&gt;&lt;P&gt;But I don't see an option to "threat-detection syn-attack shun".&lt;/P&gt;&lt;P&gt;This is on a 5585 running 8.2(5).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 03:57:20 GMT</pubDate>
    <dc:creator>brianhill88</dc:creator>
    <dc:date>2019-03-12T03:57:20Z</dc:date>
    <item>
      <title>ASA 5585 - Can I shun syn attacks as well as scanning threats?</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-can-i-shun-syn-attacks-as-well-as-scanning-threats/m-p/2464230#M268270</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I see that with threat-detection enabled and configured, I can use the "threat-detection scanning-threat shun duration [time in seconds]" to shun IPs that are scanning for open ports.&lt;/P&gt;&lt;P&gt;Is there a way to shun syn-attacks that I have a threshold set for?&lt;/P&gt;&lt;P&gt;For example I can configure this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;threat-detection rate syn-attack rate-interval 600 average-rate 30 burst-rate 45&lt;/P&gt;&lt;P&gt;But I don't see an option to "threat-detection syn-attack shun".&lt;/P&gt;&lt;P&gt;This is on a 5585 running 8.2(5).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:57:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-can-i-shun-syn-attacks-as-well-as-scanning-threats/m-p/2464230#M268270</guid>
      <dc:creator>brianhill88</dc:creator>
      <dc:date>2019-03-12T03:57:20Z</dc:date>
    </item>
    <item>
      <title>The answer to this is you can</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-can-i-shun-syn-attacks-as-well-as-scanning-threats/m-p/2464231#M268271</link>
      <description>&lt;P&gt;The answer to this is you can not. &amp;nbsp;At least not in this way.&lt;/P&gt;&lt;P&gt;What you can do is create a policy-map on the outside interface (or add a class-map if you already have an existing policy-map on the outside) and under connection settings limit the amount of per client embryonic connections.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2014 16:04:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-can-i-shun-syn-attacks-as-well-as-scanning-threats/m-p/2464231#M268271</guid>
      <dc:creator>brianhill88</dc:creator>
      <dc:date>2014-03-20T16:04:00Z</dc:date>
    </item>
  </channel>
</rss>

