<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACL issue &amp; DOS attack in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-issue-dos-attack/m-p/1686691#M529635</link>
    <description>&lt;P&gt;I have the specified configurations on my 2821 router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;&lt;P&gt; ip address 66.x.x.x 255.255.255.248&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip access-group INBOUND in&lt;/P&gt;&lt;P&gt;&amp;nbsp; no ip redirects&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip nbar protocol-discovery&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect fw out&lt;/P&gt;&lt;P&gt;&amp;nbsp; speed 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; full-duplex&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input FTP-QoS&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy output FTP-QoS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Following is the fw desctiption applied on outbound direction.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw dns&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw tcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw udp&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw icmp&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw http&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw https&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw pop3&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw imap3&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw ntp&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw ftps&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw isakmp&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw ipsec-msft&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw l2tp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Inbound ACL Description.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Extended IP access list INBOUND&lt;/P&gt;&lt;P&gt;100 permit tcp any host 66.x.x.x eq 22 log (51 matches)&lt;/P&gt;&lt;P&gt; 110 permit tcp any 209.x.x.0 0.0.0.255 eq 10111 log (9089431 matches)&lt;/P&gt;&lt;P&gt; 120 permit tcp any 209.x.x.0 0.0.0.255 eq 10112 log&lt;/P&gt;&lt;P&gt; 130 permit tcp any 209.x.x.0 0.0.0.255 eq 10113 log (11781 matches)&lt;/P&gt;&lt;P&gt; 140 permit tcp any 209.x.x.0 0.0.0.255 eq 10311 log (800041 matches)&lt;/P&gt;&lt;P&gt; 150 permit tcp any 209.x.x.0 0.0.0.255 eq 10313 log (1423114 matches)&lt;/P&gt;&lt;P&gt; 160 permit tcp any 209.x.x.0 0.0.0.255 eq 10315 log&lt;/P&gt;&lt;P&gt;&amp;nbsp; 170 permit tcp any 209.x.x.0 0.0.0.255 eq 10316 log&lt;/P&gt;&lt;P&gt;&amp;nbsp; 180 permit tcp any 209.x.x.0 0.0.0.255 eq 10321 log (417 matches)&lt;/P&gt;&lt;P&gt; 1700 permit tcp any any established log (175963 matches)&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1710 permit icmp any any echo-reply log (1 match)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 1720 deny ip any any log (211516 matches)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have recently attacked by a DOS attack in which source port was 80 , is there any issues with my configs . As according to the above configs port 80 isnt allowed in .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can any one please confirm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:48:17 GMT</pubDate>
    <dc:creator>imranraheel</dc:creator>
    <dc:date>2019-03-11T20:48:17Z</dc:date>
    <item>
      <title>ACL issue &amp; DOS attack</title>
      <link>https://community.cisco.com/t5/network-security/acl-issue-dos-attack/m-p/1686691#M529635</link>
      <description>&lt;P&gt;I have the specified configurations on my 2821 router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;&lt;P&gt; ip address 66.x.x.x 255.255.255.248&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip access-group INBOUND in&lt;/P&gt;&lt;P&gt;&amp;nbsp; no ip redirects&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip nbar protocol-discovery&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect fw out&lt;/P&gt;&lt;P&gt;&amp;nbsp; speed 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; full-duplex&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input FTP-QoS&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy output FTP-QoS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Following is the fw desctiption applied on outbound direction.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw dns&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw tcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw udp&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw icmp&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw http&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw https&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw pop3&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw imap3&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw ntp&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw ftps&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw isakmp&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw ipsec-msft&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip inspect name fw l2tp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Inbound ACL Description.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Extended IP access list INBOUND&lt;/P&gt;&lt;P&gt;100 permit tcp any host 66.x.x.x eq 22 log (51 matches)&lt;/P&gt;&lt;P&gt; 110 permit tcp any 209.x.x.0 0.0.0.255 eq 10111 log (9089431 matches)&lt;/P&gt;&lt;P&gt; 120 permit tcp any 209.x.x.0 0.0.0.255 eq 10112 log&lt;/P&gt;&lt;P&gt; 130 permit tcp any 209.x.x.0 0.0.0.255 eq 10113 log (11781 matches)&lt;/P&gt;&lt;P&gt; 140 permit tcp any 209.x.x.0 0.0.0.255 eq 10311 log (800041 matches)&lt;/P&gt;&lt;P&gt; 150 permit tcp any 209.x.x.0 0.0.0.255 eq 10313 log (1423114 matches)&lt;/P&gt;&lt;P&gt; 160 permit tcp any 209.x.x.0 0.0.0.255 eq 10315 log&lt;/P&gt;&lt;P&gt;&amp;nbsp; 170 permit tcp any 209.x.x.0 0.0.0.255 eq 10316 log&lt;/P&gt;&lt;P&gt;&amp;nbsp; 180 permit tcp any 209.x.x.0 0.0.0.255 eq 10321 log (417 matches)&lt;/P&gt;&lt;P&gt; 1700 permit tcp any any established log (175963 matches)&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1710 permit icmp any any echo-reply log (1 match)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 1720 deny ip any any log (211516 matches)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have recently attacked by a DOS attack in which source port was 80 , is there any issues with my configs . As according to the above configs port 80 isnt allowed in .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can any one please confirm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-issue-dos-attack/m-p/1686691#M529635</guid>
      <dc:creator>imranraheel</dc:creator>
      <dc:date>2019-03-11T20:48:17Z</dc:date>
    </item>
    <item>
      <title>ACL issue &amp; DOS attack</title>
      <link>https://community.cisco.com/t5/network-security/acl-issue-dos-attack/m-p/1686692#M529638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your FW is inspecting all outgoing http traffic so that return packets are allowed through the acl applied inbound on the interface. The return packets will have the source port of 80 so its possible that if there is man-in-the middle attacks somebody hijacks the initial connection going on destination port 80 and responds with source port of 80. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jun 2011 22:45:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-issue-dos-attack/m-p/1686692#M529638</guid>
      <dc:creator>andhingr</dc:creator>
      <dc:date>2011-06-23T22:45:10Z</dc:date>
    </item>
  </channel>
</rss>

