<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5510 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510/m-p/1172684#M875252</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm receiving the same messages on log:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;[ Scanning] drop rate-1 exceeded. Current burst rate is 10 per second, max configured rate is 10; Current average rate is 9 per second, max configured rate is 5; Cumulative total count is 5622&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;[ Scanning] drop rate-2 exceeded. Current burst rate is 8 per second, max configured rate is 8; Current average rate is 8 per second, max configured rate is 4; Cumulative total count is 31781&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;[ Scanning] drop rate-1 exceeded. Current burst rate is 10 per second, max configured rate is 10; Current average rate is 9 per second, max configured rate is 5; Cumulative total count is 5915&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;[ Scanning] drop rate-2 exceeded. Current burst rate is 8 per second, max configured rate is 8; Current average rate is 8 per second, max configured rate is 4; Cumulative total count is 31911&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;[ Scanning] drop rate-1 exceeded. Current burst rate is 10 per second, max configured rate is 10; Current average rate is 9 per second, max configured rate is 5; Cumulative total count is 5915&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It happens all the time.&lt;/P&gt;&lt;P&gt; It doesn't show the source or destination.&lt;/P&gt;&lt;P&gt;I'm using ASDM 6.1 - ASA 5510&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I avoid this messagens and protect from this scanning attacks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank's,&lt;/P&gt;&lt;P&gt;Renato&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 Feb 2012 15:01:26 GMT</pubDate>
    <dc:creator>renatoaureliano</dc:creator>
    <dc:date>2012-02-17T15:01:26Z</dc:date>
    <item>
      <title>ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510/m-p/1172680#M875248</link>
      <description>&lt;P&gt;All-&lt;/P&gt;&lt;P&gt;What is this message I see in the fws log?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[ Scanning] drop rate-1 exceeded.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Vlad&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:02:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510/m-p/1172680#M875248</guid>
      <dc:creator>hunnetvl01</dc:creator>
      <dc:date>2019-03-11T15:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510/m-p/1172681#M875249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please check the following link for the explannation.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html#wp4963969" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html#wp4963969&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Mar 2009 20:57:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510/m-p/1172681#M875249</guid>
      <dc:creator>Yudong Wu</dc:creator>
      <dc:date>2009-03-09T20:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510/m-p/1172682#M875250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By the way "scanning drop" includes:&lt;/P&gt;&lt;P&gt;ACL drop, Bad packet drop, Conn limit drop, ICMP drop, Inspect drop, Interface drop and Syn attack.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Mar 2009 21:04:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510/m-p/1172682#M875250</guid>
      <dc:creator>Yudong Wu</dc:creator>
      <dc:date>2009-03-09T21:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510/m-p/1172683#M875251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;is there a way I can check what hosts were previously shunned if now I cant see any.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the log which says rate exceeded but I want to see which were the shunned hosts.&lt;/P&gt;&lt;P&gt;I cant see any with sh threat-detection shun&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;V&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Mar 2009 13:21:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510/m-p/1172683#M875251</guid>
      <dc:creator>hunnetvl01</dc:creator>
      <dc:date>2009-03-10T13:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510/m-p/1172684#M875252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm receiving the same messages on log:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;[ Scanning] drop rate-1 exceeded. Current burst rate is 10 per second, max configured rate is 10; Current average rate is 9 per second, max configured rate is 5; Cumulative total count is 5622&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;[ Scanning] drop rate-2 exceeded. Current burst rate is 8 per second, max configured rate is 8; Current average rate is 8 per second, max configured rate is 4; Cumulative total count is 31781&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;[ Scanning] drop rate-1 exceeded. Current burst rate is 10 per second, max configured rate is 10; Current average rate is 9 per second, max configured rate is 5; Cumulative total count is 5915&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;[ Scanning] drop rate-2 exceeded. Current burst rate is 8 per second, max configured rate is 8; Current average rate is 8 per second, max configured rate is 4; Cumulative total count is 31911&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;[ Scanning] drop rate-1 exceeded. Current burst rate is 10 per second, max configured rate is 10; Current average rate is 9 per second, max configured rate is 5; Cumulative total count is 5915&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It happens all the time.&lt;/P&gt;&lt;P&gt; It doesn't show the source or destination.&lt;/P&gt;&lt;P&gt;I'm using ASDM 6.1 - ASA 5510&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I avoid this messagens and protect from this scanning attacks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank's,&lt;/P&gt;&lt;P&gt;Renato&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Feb 2012 15:01:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510/m-p/1172684#M875252</guid>
      <dc:creator>renatoaureliano</dc:creator>
      <dc:date>2012-02-17T15:01:26Z</dc:date>
    </item>
    <item>
      <title>ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510/m-p/1172685#M875253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Found Solution for drop rate-1:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/thread/228276"&gt;https://supportforums.cisco.com/thread/228276&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The syslogs "[ Scanning] drop rate-1 exceeded." mean the you have exceeded the "Scanning attack detected" threshold.&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Shows a threshold that you exceeded.&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;But threat detection will not drop unless you tell it to.&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;The default behavior is to just alert (generate syslog).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;So I would like to know if drop rate-2 is the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Thank's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Feb 2012 19:31:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510/m-p/1172685#M875253</guid>
      <dc:creator>renatoaureliano</dc:creator>
      <dc:date>2012-02-17T19:31:49Z</dc:date>
    </item>
  </channel>
</rss>

