<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5510 Syn attacks in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326688#M310476</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Duncan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okey you provide us information ( a screenshoot even &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt; ) but what is the problem exactly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you want to prevent DoS attacks? what are you looking for at this moment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 Oct 2013 13:37:29 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-10-23T13:37:29Z</dc:date>
    <item>
      <title>ASA 5510 Syn attacks</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326687#M310475</link>
      <description>&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/5/8/9/162985-ASA%20Firewall%20Dashboard%20caprute..JPG" alt="ASA Firewall Dashboard caprute..JPG" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could anyone assist me help the above issuse, I had already created a discussion and was helped by&lt;/P&gt;&lt;P&gt;one of the community but could not resolve the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached a link in regards to carrying out troubleshooting with &lt;A _jive_internal="true" href="https://community.cisco.com/people/JouniForss" id="jive-218644905253783710135" onmouseout="" onmouseover="" target="_blank"&gt;JouniForss&lt;/A&gt; but I could not resolve the fault&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/thread/2245710" target="_blank"&gt;https://supportforums.cisco.com/thread/2245710&lt;/A&gt;&amp;nbsp; prevoiusly created discussion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have even rolled the asa config back to an earlier version which was allowing the partners site 62.233.82.181 on port 80&amp;nbsp; access and now it does not, if anyone has come across this issue and have resolved it could you please let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards. &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:55:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326687#M310475</guid>
      <dc:creator>Highnet_TSC</dc:creator>
      <dc:date>2019-03-12T02:55:12Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 Syn attacks</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326688#M310476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Duncan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okey you provide us information ( a screenshoot even &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt; ) but what is the problem exactly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you want to prevent DoS attacks? what are you looking for at this moment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 13:37:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326688#M310476</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-10-23T13:37:29Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 Syn attacks</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326689#M310477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Julio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that our network connected to the ASA router on the inside, address range 192.168.254.0 /24 cannot&lt;/P&gt;&lt;P&gt;reach our partners site at 62.233.82.181 on port 80 connected on the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This seems to be the only website that we cannot access everything else that is going through our ASA firewall is returning back this includes all other websites we visit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I would like to do is be able to setup a access rule or policy to resolve this as you can see from the screen shot, there is some sort of syn attack.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I mentioned above we rolled back to an earlier config that was allowing as access to the partners web site but for some reason does not any more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 15:42:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326689#M310477</guid>
      <dc:creator>Highnet_TSC</dc:creator>
      <dc:date>2013-10-23T15:42:51Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 Syn attacks</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326690#M310478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Duncan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I now understand your issue,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post or send me the configuration with the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jcarvaja&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;follow me on &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 19:16:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326690#M310478</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-10-23T19:16:18Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 Syn attacks</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326691#M310479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see how the ASA is reporting this and actually it could be related to the source not being able to receive a reply back from the destination thus reporting a SYN attack because all we see are SYN,SYN,SYN,SYN,SYN sent by the source 192.168.254.X address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I would ask of you would be the next:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know that the packet tracer already indicates that it allows it through but we need to look at the phases that it is going through so please post the output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also need the output from a working network to the remote site, the reason I need this information would be for us to confirm that they are going out via the same IP and to confirm if there are any differences.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 20:23:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326691#M310479</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-10-23T20:23:19Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 Syn attacks</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326692#M310480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I mean a packet-tracer from the working network that resides behind the ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 20:24:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326692#M310480</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-10-23T20:24:11Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 Syn attacks</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326693#M310481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you still need assistance, did any of the information given help you out?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 01:09:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326693#M310481</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-10-29T01:09:58Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 Syn attacks</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326694#M310482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please update the ticket as resolved or answered so we can close out followup.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 17:52:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326694#M310482</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-10-31T17:52:19Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 Syn attacks</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326695#M310483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Jumora&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried everything to rectify that I can think off, access-controls list creating class-maps policy maps, to include embryonic connections &lt;/P&gt;&lt;P&gt;turning off Basic threat detection. I have even connected straight into the ASA inside port that the network connects to and still cannot open or reach the partners site, but I can reach any other website on the network. Have also connected into the router which is the next hop after the ASA onto the internet and yes that does allow me to reach the partners site and open it in my web browser. So I am at a loss in trying to resolve this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have any other suggestion Jumora I would be glad to hear them and try and put them into action if possible, as this is a working network down time is hard to arrange right away&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Nov 2013 09:00:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326695#M310483</guid>
      <dc:creator>Highnet_TSC</dc:creator>
      <dc:date>2013-11-01T09:00:52Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 Syn attacks</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326696#M310484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;OK, when you put the PC in front of the ASA what IP address do you dive it, why I want to know this is because if it is any address other than the IP address that we have for PAT on the ASA and is one of the addresses on the WAN side of the ASA I will change it from the PAT just to see if after we do this change you can reach the site.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Nov 2013 02:56:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326696#M310484</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-03T02:56:03Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 Syn attacks</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326697#M310485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jumora&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The IP address I give it is a private IP address, the strange thing is that I can reach all other sites while been plugged into the Inside on the ASA firewall, however I cannot reach the &lt;A href="http://partners.highnet.com/login/"&gt;http://partners.highnet.com/login/&lt;/A&gt; ip address 62.233.82.181 cannot figure this one out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 09:15:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326697#M310485</guid>
      <dc:creator>Highnet_TSC</dc:creator>
      <dc:date>2013-11-04T09:15:58Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 Syn attacks</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326698#M310486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, we can do two things here, one open up a TAC case if you have a contract and I can help you out or two you would need to send me the configuration and tell me what IP address you placed on the PC when it was able to reach the site when it was not behind the ASA so we can try to map that address to a PAT to see if then internal users are able to reach the site.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 20:14:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326698#M310486</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-04T20:14:04Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 Syn attacks</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326699#M310487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jumora&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the details, we are now looking at setting up a smartnet account for our ASA routers and progress from there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks very much for your time and effort muct appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We can close this post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regrads&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 10:58:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326699#M310487</guid>
      <dc:creator>Highnet_TSC</dc:creator>
      <dc:date>2013-11-06T10:58:42Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 Syn attacks</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326700#M310488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please rate the answer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 17:28:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326700#M310488</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-06T17:28:32Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 Syn attacks</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326701#M310489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please rate the assistance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 22:53:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326701#M310489</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-06T22:53:25Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 Syn attacks</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326702#M310490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please rate the assistance. &lt;/P&gt;&lt;P&gt;Please rate the assistance.&lt;/P&gt;&lt;P&gt;Please rate the assistance.&lt;/P&gt;&lt;P&gt;Please rate the assistance.&lt;/P&gt;&lt;P&gt;Please rate the assistance.&lt;/P&gt;&lt;P&gt;Please rate the assistance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Nov 2013 14:49:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-syn-attacks/m-p/2326702#M310490</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-14T14:49:21Z</dc:date>
    </item>
  </channel>
</rss>

