<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Attack to interface outside ASA 5510 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/attack-to-interface-outside-asa-5510/m-p/946816#M940138</link>
    <description>&lt;P&gt;Hi, We are to pain very attack of DoS.&lt;/P&gt;&lt;P&gt;We want to know:&lt;/P&gt;&lt;P&gt;1. If we can see in the ASA which IP's and the percentage of total bandwidth usage in real time&lt;/P&gt;&lt;P&gt;2. or a software of Cisco or third to this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:24:11 GMT</pubDate>
    <dc:creator>wilmerreyes</dc:creator>
    <dc:date>2019-03-11T12:24:11Z</dc:date>
    <item>
      <title>Attack to interface outside ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/attack-to-interface-outside-asa-5510/m-p/946816#M940138</link>
      <description>&lt;P&gt;Hi, We are to pain very attack of DoS.&lt;/P&gt;&lt;P&gt;We want to know:&lt;/P&gt;&lt;P&gt;1. If we can see in the ASA which IP's and the percentage of total bandwidth usage in real time&lt;/P&gt;&lt;P&gt;2. or a software of Cisco or third to this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:24:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/attack-to-interface-outside-asa-5510/m-p/946816#M940138</guid>
      <dc:creator>wilmerreyes</dc:creator>
      <dc:date>2019-03-11T12:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: Attack to interface outside ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/attack-to-interface-outside-asa-5510/m-p/946817#M940139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also about the bandwidth utilisation unfortunately that cant be found out on Pix/ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is not possible to check with the bandwidth using syslogs at all. However, if the&lt;/P&gt;&lt;P&gt;bandwidth drops to 0 the Pix/ASA would report an error in syslog with the ID: 613002 and for&lt;/P&gt;&lt;P&gt;this you need to enable logging to level 6 (informational).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, on PDM, it would show the system resources as well as the traffic passing&lt;/P&gt;&lt;P&gt;through the Pix/ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do understand that it is difficult to interpret the the output of syslogs as it always&lt;/P&gt;&lt;P&gt;would be huge and a bit confusing but there is no way out and just to copy them on a&lt;/P&gt;&lt;P&gt;notepad/wordpad and with the help of search can check with any ip address or any other&lt;/P&gt;&lt;P&gt;string. However, you can use some 3rd party softwares and refine the search based on ip&lt;/P&gt;&lt;P&gt;addresses or any other paramenters which are predifined on the softwares and it would&lt;/P&gt;&lt;P&gt;return you a clean output of the thing you are looking for. Below are the two links for&lt;/P&gt;&lt;P&gt;two different softwares.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.reportgen.com/index.htm" target="_blank"&gt;http://www.reportgen.com/index.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.wingrep.com/download.html" target="_blank"&gt;http://www.wingrep.com/download.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For this kind of reporting, you will need to&lt;/P&gt;&lt;P&gt;have a software with reporting capability.  The following are options for&lt;/P&gt;&lt;P&gt;you:&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Cisco Products:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CS-MARS -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6241/products_user_guide_chapter09186a" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6241/products_user_guide_chapter09186a&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;00804f1622.html&lt;/P&gt;&lt;P&gt;Monitoring Center for Performance (MCP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/cscowork/ps5387/products_qanda_item09" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/cscowork/ps5387/products_qanda_item09&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;186a00801d2f47.shtml&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Some other third party products:&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Network Intelligence Engine from Network Intelligence&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(&lt;A class="jive-link-custom" href="http://www.network-intelligence.com" target="_blank"&gt;http://www.network-intelligence.com&lt;/A&gt;) &lt;/P&gt;&lt;P&gt;Network Security Analyzer and FirewallAnalyzer Enterprise from eIQnetworks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(&lt;A class="jive-link-custom" href="http://www.eiqnetworks.com" target="_blank"&gt;http://www.eiqnetworks.com&lt;/A&gt;) &lt;/P&gt;&lt;P&gt;Sawmill Log Analyzer from FlowerFire &lt;/P&gt;&lt;P&gt;(&lt;A class="jive-link-custom" href="http://www.sawmill.net" target="_blank"&gt;http://www.sawmill.net&lt;/A&gt;) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are just some to name. You can do a search on Google for other&lt;/P&gt;&lt;P&gt;applications.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Mar 2008 01:08:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/attack-to-interface-outside-asa-5510/m-p/946817#M940139</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-03-29T01:08:49Z</dc:date>
    </item>
  </channel>
</rss>

