<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Preventing DoS attacks and using encryption in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/preventing-dos-attacks-and-using-encryption/m-p/1621938#M589985</link>
    <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have setup the network as per the attached topology. All remote sites are able to access the Main site Application Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My issues are as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;How can DoS attacks on the server be prevented? Is there some configuration that can be on the routers or the firewall (Rate limiting, ACL)?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;All the routers (Cisco 3825 and 2811) are equipped with the &lt;STRONG&gt;ADVENTERPRISEK9-M&lt;/STRONG&gt; IOS and therefore contain cryptographic features. &lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Are the routers already encrypting the data which is being transmitted?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If yes, how is the encryption/decryption processes performed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If no, is there some configuration that needs to be done on the routers to turn encryption on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see attached topology.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alvin&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:02:22 GMT</pubDate>
    <dc:creator>net buzz</dc:creator>
    <dc:date>2019-03-11T20:02:22Z</dc:date>
    <item>
      <title>Preventing DoS attacks and using encryption</title>
      <link>https://community.cisco.com/t5/network-security/preventing-dos-attacks-and-using-encryption/m-p/1621938#M589985</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have setup the network as per the attached topology. All remote sites are able to access the Main site Application Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My issues are as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;How can DoS attacks on the server be prevented? Is there some configuration that can be on the routers or the firewall (Rate limiting, ACL)?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;All the routers (Cisco 3825 and 2811) are equipped with the &lt;STRONG&gt;ADVENTERPRISEK9-M&lt;/STRONG&gt; IOS and therefore contain cryptographic features. &lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Are the routers already encrypting the data which is being transmitted?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If yes, how is the encryption/decryption processes performed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If no, is there some configuration that needs to be done on the routers to turn encryption on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see attached topology.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alvin&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:02:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/preventing-dos-attacks-and-using-encryption/m-p/1621938#M589985</guid>
      <dc:creator>net buzz</dc:creator>
      <dc:date>2019-03-11T20:02:22Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing DoS attacks and using encryption</title>
      <link>https://community.cisco.com/t5/network-security/preventing-dos-attacks-and-using-encryption/m-p/1621939#M590006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To prevent DoS on an ASA level you can do some things (i found the following making a quick search in CSC):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For DDOS / DOS attacks see below a reference for configuring threat detection&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_threat.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_threat.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If&amp;nbsp; you want to provide protection for against spam, spyware, viruses,&amp;nbsp; phishing, etc that enters your network via email, HTTP, or FTP traffic&amp;nbsp; then you would use a CSC modules. See the link below&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/ps6823/product_data_sheet0900aecd80402e4f_ps6120_Products_Data_Sheet.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/ps6823/product_data_sheet0900aecd80402e4f_ps6120_Products_Data_Sheet.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See below a Q&amp;amp;A for the product&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/prod_qas0900aecd8040397e.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/prod_qas0900aecd8040397e.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An IPS modue &lt;SPAN class="content"&gt;provides&amp;nbsp; protection by blocking threats such as distributed denial of service&amp;nbsp; attacks, reconnaissance&amp;nbsp; attacks, and attacks against operating system&amp;nbsp; and application&amp;nbsp; vulnerabilities. See below&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5729/ps5713/ps4077/data_sheet_c78-459036_ps6120_Products_Data_Sheet.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5729/ps5713/ps4077/data_sheet_c78-459036_ps6120_Products_Data_Sheet.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See below a Q&amp;amp;A for the product&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5729/ps5713/ps4077/qa_c67-458612_ps6120_Products_Q_and_A_Item.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5729/ps5713/ps4077/qa_c67-458612_ps6120_Products_Q_and_A_Item.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 5510 &amp;amp; 5520's only have one expansion slot for security services modules so you can install only of these devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the other question... the fact that the routers have an advanced services image means they can encrypt the data and provide additional security features.&lt;/P&gt;&lt;P&gt;The routers are NOT encrypting the data by default.&lt;/P&gt;&lt;P&gt;They CAN be configured to encrypt data before sending packets out (as you would normally have when configuring an IPsec tunnel). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Mar 2011 01:53:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/preventing-dos-attacks-and-using-encryption/m-p/1621939#M590006</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-03-08T01:53:59Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing DoS attacks and using encryption</title>
      <link>https://community.cisco.com/t5/network-security/preventing-dos-attacks-and-using-encryption/m-p/1621940#M590016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Alvin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to add a little more to what Fedrico has shared, on IOS we can use TCP intercept feature availble in advipservicesk9 image.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are few links for your better understanding &amp;amp; reference:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/ios/12_2/security/configuration/guide/scfdenl.html"&gt;http://www.cisco.com/en/US/docs/ios/12_2/security/configuration/guide/scfdenl.html&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/ios/12_2/security/command/reference/srfenl.html"&gt;http://www.cisco.com/en/US/docs/ios/12_2/security/command/reference/srfenl.html&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. Please reply if you need further assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Chirag&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: Please mark this thread as answered if you feel your query is answered. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Mar 2011 02:03:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/preventing-dos-attacks-and-using-encryption/m-p/1621940#M590016</guid>
      <dc:creator>csaxena</dc:creator>
      <dc:date>2011-03-08T02:03:11Z</dc:date>
    </item>
  </channel>
</rss>

