<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to prevent SYN Flood with IOS Firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-prevent-syn-flood-with-ios-firewall/m-p/1554153#M615591</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Engage tcp intercept for syn flood attack.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/ios/11_3/security/configuration/guide/scdenial.html#wp3654"&gt;http://www.cisco.com/en/US/docs/ios/11_3/security/configuration/guide/scdenial.html#wp3654&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Dec 2010 04:34:14 GMT</pubDate>
    <dc:creator>Kureli Sankar</dc:creator>
    <dc:date>2010-12-02T04:34:14Z</dc:date>
    <item>
      <title>How to prevent SYN Flood with IOS Firewall</title>
      <link>https://community.cisco.com/t5/network-security/how-to-prevent-syn-flood-with-ios-firewall/m-p/1554151#M615589</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm deploying ASR1000 (also known IOS Firewall), and would like to prevent some network attacks like below with IOS Firewall. I believe there are some commands that can be configured in ASR, but i'm not sure how to use them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) SYN Flood attack&lt;/P&gt;&lt;P&gt;2) IP fragmentation attack&lt;/P&gt;&lt;P&gt;3) Detect and record the port scanning behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Alejin&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:17:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-prevent-syn-flood-with-ios-firewall/m-p/1554151#M615589</guid>
      <dc:creator>proactive99</dc:creator>
      <dc:date>2019-03-11T19:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent SYN Flood with IOS Firewall</title>
      <link>https://community.cisco.com/t5/network-security/how-to-prevent-syn-flood-with-ios-firewall/m-p/1554152#M615590</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) You can set connection limits for the Zone Based Firewall to not pass many connections. But if someone start the SYN flood the firewall cannot really prevent it. It can block it, but you can't stop someone from doing it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) The ASR1K Zone Based Firewall feature can be set to drop fragments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) An IPS would do that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generally speaking all the above can also be done and you can be notified for them better from an IPS/IDS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps a little.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Dec 2010 23:56:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-prevent-syn-flood-with-ios-firewall/m-p/1554152#M615590</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-12-01T23:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent SYN Flood with IOS Firewall</title>
      <link>https://community.cisco.com/t5/network-security/how-to-prevent-syn-flood-with-ios-firewall/m-p/1554153#M615591</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Engage tcp intercept for syn flood attack.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/ios/11_3/security/configuration/guide/scdenial.html#wp3654"&gt;http://www.cisco.com/en/US/docs/ios/11_3/security/configuration/guide/scdenial.html#wp3654&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Dec 2010 04:34:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-prevent-syn-flood-with-ios-firewall/m-p/1554153#M615591</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-12-02T04:34:14Z</dc:date>
    </item>
  </channel>
</rss>

