<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Scanning Attacks &amp; Syn Attacks in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123547#M915217</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So does 'show threat-detection shun' show the attacker being shunned?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Aug 2008 17:33:46 GMT</pubDate>
    <dc:creator>robertson.michael</dc:creator>
    <dc:date>2008-08-06T17:33:46Z</dc:date>
    <item>
      <title>Scanning Attacks &amp; Syn Attacks</title>
      <link>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123541#M915208</link>
      <description>&lt;P&gt;Hey all, I have enabled basic threat detection, and also enabled auto shun in hopes to speed up our web server. Using the CLI I have found 2 latest attack host list and 1 in the latest target host list. But nothing in the shun list. I understand that the shun list is enabled once some thresholds are exceeded but I've got nothing shun'ed yet. And my possible scan and Syn attack rates is always fluctuating from 1 - 25. Is there something I've missed? &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:26:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123541#M915208</guid>
      <dc:creator>netperception</dc:creator>
      <dc:date>2019-03-11T13:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning Attacks &amp; Syn Attacks</title>
      <link>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123542#M915211</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would recommend checking out the config guide for threat-detection:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/protect.html#wp1072953" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/protect.html#wp1072953&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Specifically, you'll need the following command before the ASA will automatically shun attackers:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)# threat-detection scanning-threat shun&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If everything looks like it is in order, please post the output of 'show run threat'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Aug 2008 21:22:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123542#M915211</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2008-08-05T21:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning Attacks &amp; Syn Attacks</title>
      <link>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123543#M915213</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Result of the command: "show run threat"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection scanning-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 13:39:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123543#M915213</guid>
      <dc:creator>netperception</dc:creator>
      <dc:date>2008-08-06T13:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning Attacks &amp; Syn Attacks</title>
      <link>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123544#M915214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection scanning-threat shun except ip-address INT.21_SERVER1_ALPHA 255.255.255.255&lt;/P&gt;&lt;P&gt;threat-detection statistics&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 14:17:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123544#M915214</guid>
      <dc:creator>netperception</dc:creator>
      <dc:date>2008-08-06T14:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning Attacks &amp; Syn Attacks</title>
      <link>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123545#M915215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your previous post, you did not have 'threat-detection scanning-threat shun' enabled. However, in the second post you do. Was this showing the change you made?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the 'threat-detection scanning-threat shun' command do you still not see attackers being shunned?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 16:59:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123545#M915215</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2008-08-06T16:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning Attacks &amp; Syn Attacks</title>
      <link>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123546#M915216</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Result of the command: "threat-detection scanning-threat shun"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command has been sent to the device&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;Result of the command: "show threat-detection scanning-threat"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Latest Target Host List:&lt;/P&gt;&lt;P&gt;    207.61.11.0&lt;/P&gt;&lt;P&gt;Latest Attacker Host List:&lt;/P&gt;&lt;P&gt;    INT.21_SERVER1_ALPHA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 17:28:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123546#M915216</guid>
      <dc:creator>netperception</dc:creator>
      <dc:date>2008-08-06T17:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning Attacks &amp; Syn Attacks</title>
      <link>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123547#M915217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So does 'show threat-detection shun' show the attacker being shunned?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 17:33:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123547#M915217</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2008-08-06T17:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning Attacks &amp; Syn Attacks</title>
      <link>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123548#M915218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey, sorry. Thanks btw. I did make a change after I read your first email. It made sense that nothing was being shun'ed till I turned it on through the CLI. But what led me to believe I had it turned on was that i use the desktop application to administor this and I had checked the shun check box. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To answer 'do I see attackers in my shun list'. No, for some reason I still do not, and my graph is so erratic. Fluctuates from 0 to 14 for scanning and 0 to 3 for syn. When I posted the results of 2 cli commands the first one shows some possibles, and it shows nothing is being shun'ed. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 17:47:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123548#M915218</guid>
      <dc:creator>netperception</dc:creator>
      <dc:date>2008-08-06T17:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning Attacks &amp; Syn Attacks</title>
      <link>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123549#M915219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The attacker list that you posted shows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Latest Attacker Host List:&lt;/P&gt;&lt;P&gt;INT.21_SERVER1_ALPHA &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, the configuration you posted was:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;threat-detection scanning-threat shun except ip-address INT.21_SERVER1_ALPHA 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above line means that we should shun all attacking hosts *except* INT.21_SERVER1_ALPHA. Therefore, since this is currently the only host in the attacker list, we will not shun this host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you want to shun the INT.21_SERVER1_ALPHA host? If not, your configuration is correct. If you do not want shun this host, you'd want to configure the following commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)# no threat-detection scanning-threat shun except ip-address INT.21_SERVER1_ALPHA 255.255.255.255&lt;/P&gt;&lt;P&gt;ASA(config)# threat-detectoin scanning-threat shun&lt;/P&gt;&lt;P&gt;ASA# wr mem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 21:18:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123549#M915219</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2008-08-06T21:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning Attacks &amp; Syn Attacks</title>
      <link>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123550#M915220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure does help. My main concern is that we haven't blocked anyone yet. And the scan syn attack chart goes between 0 and 4 hiting over 10 atleast a few times an hour (but would have to verify). The chart hits 0, but most of the time is running around 1. &lt;/P&gt;&lt;P&gt;I just had a thought, you think the chart includes the exempted ips? So say if there's 3 that I know of and I exempt them, and they were the only ones the chart would show the exempts?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 12:05:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123550#M915220</guid>
      <dc:creator>netperception</dc:creator>
      <dc:date>2008-08-07T12:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning Attacks &amp; Syn Attacks</title>
      <link>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123551#M915221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, that chart will include all attackers since these are based on the statistics calculated by threat-detection. Once the attackers are established and known, it will decide whether or not to shun them based on whether or not you explicitly exempt them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you remove the exempt portion threat-detection command, you should see that the attacker is then shunned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 23:01:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123551#M915221</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2008-08-07T23:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning Attacks &amp; Syn Attacks</title>
      <link>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123552#M915222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Mike. I'm beginning to see hosts that are shunned. and after doing background look-up (whois stuff) on them prior I knew they were bad and now they are shunned. I guess what I had read was ok as it was a static explanation but your real time explanation matched with what happened last couple days for a great resolution. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, dare I ask,... have you found yourself changing any of the threshold values?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chuck&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Aug 2008 12:44:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123552#M915222</guid>
      <dc:creator>netperception</dc:creator>
      <dc:date>2008-08-08T12:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning Attacks &amp; Syn Attacks</title>
      <link>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123553#M915223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kind of a cross post, but I have about 6 or so known IP's showing up in the top usage pie chart. I don't really care to conviently see them so is there a way to exclude the 6 ips (I even named them), so I can see the the top usage of other IP's? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm also reading the cli documentation but lots to read, is there a cli command to list the top X usage by ip&amp;amp;packets?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Aug 2008 12:48:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123553#M915223</guid>
      <dc:creator>netperception</dc:creator>
      <dc:date>2008-08-08T12:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning Attacks &amp; Syn Attacks</title>
      <link>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123554#M915226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chuck,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the answers to your questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. The default scanning rates are typically fine for most people, though you can adjust them with the 'threat-detection rate' command. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Unfortunately, there is no way to exclude these IP addresses from showing up in the statistics.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. When 'threat-detection statistics' is enabled, you can issue the 'show threat-detection statistics top host' command. This will show you the top source and destination IP addresses and the packet rates for each.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Aug 2008 20:30:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123554#M915226</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2008-08-08T20:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning Attacks &amp; Syn Attacks</title>
      <link>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123555#M915227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, thanks again. But I guess even in the CLI I can not view more then the top 10?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2008 13:14:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123555#M915227</guid>
      <dc:creator>netperception</dc:creator>
      <dc:date>2008-08-11T13:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning Attacks &amp; Syn Attacks</title>
      <link>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123556#M915230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chuck,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, that's correct. You'll only get the top 10.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2008 22:06:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scanning-attacks-syn-attacks/m-p/1123556#M915230</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2008-08-11T22:06:18Z</dc:date>
    </item>
  </channel>
</rss>

