<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic USers could not access Web Pages in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/users-could-not-access-web-pages/m-p/2303116#M342613</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Thread-detection feature noticed that the your DNS servers sending an abnornal amount of traffic (or at least something that exceded the default parameters.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem here was that when your internal PCs tried to resolve a website they query the internal DNS server but it was unable to access the internet because it was shunned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure your PC/Servers are not infected by any kind of Virus/Botnet. End-point protection is very important in this cases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see the ASA is doing its job &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;. BTF (Botnet traffic filter) will be a good feature to have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Luis Silva &lt;BR /&gt; &lt;BR /&gt;"If you need PDI (Planning, Design, Implement) assistance feel free to reach us" &lt;BR /&gt; &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/web/partners/tools/pdihd.html"&gt;http://www.cisco.com/web/partners/tools/pdihd.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Sep 2013 20:01:11 GMT</pubDate>
    <dc:creator>Luis Silva Benavides</dc:creator>
    <dc:date>2013-09-25T20:01:11Z</dc:date>
    <item>
      <title>USers could not access Web Pages</title>
      <link>https://community.cisco.com/t5/network-security/users-could-not-access-web-pages/m-p/2303115#M342612</link>
      <description>&lt;P&gt;Last Night my users were unable to surf the web, other services, such as email and FTP were available.&amp;nbsp; I eventually noticed numerous "Shunned Packet" warnings when examining the ASA_5520 Syslog for the time period in question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;2013-09-22 20:28:47&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Local7.Warning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;asa-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sep 22 2013 20:28:47: %ASA-4-401004: Shunned packet:&amp;nbsp; x.x.20.27 ==&amp;gt; 75.75.75.75 on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;2013-09-22 20:28:48&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Local7.Warning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;asa-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sep 22 2013 20:28:48: %ASA-4-401004: Shunned packet:&amp;nbsp; x.x.20.26 ==&amp;gt; 75.75.75.75 on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;2013-09-22 20:28:48&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Local7.Warning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;asa-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sep 22 2013 20:28:48: %ASA-4-401004: Shunned packet:&amp;nbsp; x.x.20.26 ==&amp;gt; 75.75.75.75 on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;2013-09-22 20:28:48&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Local7.Warning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;asa-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sep 22 2013 20:28:48: %ASA-4-401004: Shunned packet:&amp;nbsp; x.x.20.27 ==&amp;gt; 75.75.75.75 on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;2013-09-22 20:28:48&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Local7.Warning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;asa-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sep 22 2013 20:28:48: %ASA-4-401004: Shunned packet:&amp;nbsp; x.x.20.27 ==&amp;gt; 75.75.76.76 on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;2013-09-22 20:28:48&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Local7.Warning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;asa-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sep 22 2013 20:28:48: %ASA-4-401004: Shunned packet:&amp;nbsp; x.x.20.27 ==&amp;gt; 75.75.75.75 on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;2013-09-22 20:28:48&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Local7.Warning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;asa-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sep 22 2013 20:28:48: %ASA-4-401004: Shunned packet:&amp;nbsp; x.x.20.26 ==&amp;gt; 24.143.246.29 on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;2013-09-22 20:28:48&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Local7.Warning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;asa-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sep 22 2013 20:28:48: %ASA-4-401004: Shunned packet:&amp;nbsp; x.x.20.26 ==&amp;gt; 24.143.246.29 on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;2013-09-22 20:28:48&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Local7.Warning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;asa-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sep 22 2013 20:28:48: %ASA-4-401004: Shunned packet:&amp;nbsp; x.x.20.26 ==&amp;gt; 24.143.246.29 on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;2013-09-22 20:28:48&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Local7.Warning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;asa-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sep 22 2013 20:28:48: %ASA-4-401004: Shunned packet:&amp;nbsp; x.x.20.26 ==&amp;gt; 205.152.144.23 on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;2013-09-22 20:28:48&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Local7.Warning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;asa-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sep 22 2013 20:28:48: %ASA-4-401004: Shunned packet:&amp;nbsp; x.x.20.26 ==&amp;gt; 205.152.144.23 on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;2013-09-22 20:28:48&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Local7.Warning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;asa-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sep 22 2013 20:28:48: %ASA-4-401004: Shunned packet:&amp;nbsp; x.x.20.26 ==&amp;gt; 205.152.144.23 on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;2013-09-22 20:28:48&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Local7.Warning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;asa-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sep 22 2013 20:28:48: %ASA-4-401004: Shunned packet:&amp;nbsp; x.x.20.26 ==&amp;gt; 205.152.144.23 on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;2013-09-22 20:28:48&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Local7.Warning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;asa-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sep 22 2013 20:28:48: %ASA-4-401004: Shunned packet:&amp;nbsp; x.x.20.26 ==&amp;gt; 205.152.144.23 on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;2013-09-22 20:28:48&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Local7.Warning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;asa-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sep 22 2013 20:28:48: %ASA-4-401004: Shunned packet:&amp;nbsp; x.x.20.26 ==&amp;gt; 205.152.144.23 on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;2013-09-22 20:28:48&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Local7.Warning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;asa-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sep 22 2013 20:28:48: %ASA-4-401004: Shunned packet:&amp;nbsp; x.x.20.26 ==&amp;gt; 75.75.75.75 on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;2013-09-22 20:28:48&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Local7.Warning&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;asa-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sep 22 2013 20:28:48: %ASA-4-401004: Shunned packet:&amp;nbsp; x.x.20.27 ==&amp;gt; 75.75.75.75 on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 20.26 and 20.27 IP's are my Private DNS Servers, so I am suspecting I was having some kind of DNS attack. I eventually rebooted both of these servers and my problems went away.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess my question is, what else can I look for that will help me determine if this was some kind of denial of service attack? And, if it was an attack, how do I prevent this in the future and what is the best way to recover?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jeff&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:42:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-could-not-access-web-pages/m-p/2303115#M342612</guid>
      <dc:creator>jeggleston</dc:creator>
      <dc:date>2019-03-12T02:42:15Z</dc:date>
    </item>
    <item>
      <title>USers could not access Web Pages</title>
      <link>https://community.cisco.com/t5/network-security/users-could-not-access-web-pages/m-p/2303116#M342613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Thread-detection feature noticed that the your DNS servers sending an abnornal amount of traffic (or at least something that exceded the default parameters.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem here was that when your internal PCs tried to resolve a website they query the internal DNS server but it was unable to access the internet because it was shunned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure your PC/Servers are not infected by any kind of Virus/Botnet. End-point protection is very important in this cases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see the ASA is doing its job &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;. BTF (Botnet traffic filter) will be a good feature to have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Luis Silva &lt;BR /&gt; &lt;BR /&gt;"If you need PDI (Planning, Design, Implement) assistance feel free to reach us" &lt;BR /&gt; &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/web/partners/tools/pdihd.html"&gt;http://www.cisco.com/web/partners/tools/pdihd.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Sep 2013 20:01:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-could-not-access-web-pages/m-p/2303116#M342613</guid>
      <dc:creator>Luis Silva Benavides</dc:creator>
      <dc:date>2013-09-25T20:01:11Z</dc:date>
    </item>
  </channel>
</rss>

