<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Port scans (attacks?) on Cisco ASA slowing down internet in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/port-scans-attacks-on-cisco-asa-slowing-down-internet/m-p/3381803#M958640</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I cannot seem to find a topic for this and perhaps I'm using the wrong searches; so I'm apologizing ahead of time if this is somehow a duplicate discussion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I support a location that has Cisco ASA in place and periodically their internet bandwidth drops tremendously, to the point that the internet is not usable.&amp;nbsp; I monitor their router speeds for traffic in and out and during these times bandwidth usage is normal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I found that happens is that there are many port scans happening at that time and it repeatedly exceeds the port scan limit.&amp;nbsp; It seems that the ASA see it and is doing its job, but it happens so much that I think the ASA is getting overburdened by responding to continuous scans from so many sources that it is requiring most of the resources it has.&amp;nbsp; So effectively, their "internet is down".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to find out if there is something extra I need to put into place.&amp;nbsp; Maybe the basic security is not configured properly or I need to adjust rules.&amp;nbsp; Perhaps add something new.&amp;nbsp; I do not have Firepower or anything extra in play here.&amp;nbsp; This is a Cisco ASA 5512-X running software version 9.6(1)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mike&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:45:27 GMT</pubDate>
    <dc:creator>mvelatln</dc:creator>
    <dc:date>2020-02-21T15:45:27Z</dc:date>
    <item>
      <title>Port scans (attacks?) on Cisco ASA slowing down internet</title>
      <link>https://community.cisco.com/t5/network-security/port-scans-attacks-on-cisco-asa-slowing-down-internet/m-p/3381803#M958640</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I cannot seem to find a topic for this and perhaps I'm using the wrong searches; so I'm apologizing ahead of time if this is somehow a duplicate discussion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I support a location that has Cisco ASA in place and periodically their internet bandwidth drops tremendously, to the point that the internet is not usable.&amp;nbsp; I monitor their router speeds for traffic in and out and during these times bandwidth usage is normal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I found that happens is that there are many port scans happening at that time and it repeatedly exceeds the port scan limit.&amp;nbsp; It seems that the ASA see it and is doing its job, but it happens so much that I think the ASA is getting overburdened by responding to continuous scans from so many sources that it is requiring most of the resources it has.&amp;nbsp; So effectively, their "internet is down".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to find out if there is something extra I need to put into place.&amp;nbsp; Maybe the basic security is not configured properly or I need to adjust rules.&amp;nbsp; Perhaps add something new.&amp;nbsp; I do not have Firepower or anything extra in play here.&amp;nbsp; This is a Cisco ASA 5512-X running software version 9.6(1)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:45:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-scans-attacks-on-cisco-asa-slowing-down-internet/m-p/3381803#M958640</guid>
      <dc:creator>mvelatln</dc:creator>
      <dc:date>2020-02-21T15:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: Port scans (attacks?) on Cisco ASA slowing down internet</title>
      <link>https://community.cisco.com/t5/network-security/port-scans-attacks-on-cisco-asa-slowing-down-internet/m-p/3381850#M958641</link>
      <description>What tool/method did you use to see the traffic scan? &lt;BR /&gt;Can you be more specific about the type of attack? How much time is this usually taking?&lt;BR /&gt;What's the average no of connections, respectively what do you see during the attack?&lt;BR /&gt;&lt;BR /&gt;What I would do right of the bat: call/contact ISP and tell him about your issue. Maybe they're willing to help and mitigate the attack (if the case), without you adding extra security devices.&lt;BR /&gt;&lt;BR /&gt;Otherwise you'll have to bring reinforcements.&lt;BR /&gt;</description>
      <pubDate>Fri, 11 May 2018 14:02:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-scans-attacks-on-cisco-asa-slowing-down-internet/m-p/3381850#M958641</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-05-11T14:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: Port scans (attacks?) on Cisco ASA slowing down internet</title>
      <link>https://community.cisco.com/t5/network-security/port-scans-attacks-on-cisco-asa-slowing-down-internet/m-p/3381908#M958642</link>
      <description>&lt;P&gt;Thank you for the questions.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;As a side bar to the current location at hand we did have a location get hit daily around roughly the same time for the same amount of time.&amp;nbsp; During that time frame the internet was nearly unusable.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did also connect with the ISP and they really didn't suggest anything ground breaking because it wasn't a bandwidth or DDoS issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The scans showed up in the Cisco log when set to "Warnings".&amp;nbsp; There were over 700 unique IP addresses doing port scans on their ASA.&amp;nbsp; From what I know the basic scan limit is there and it drops them but it still hits the box and has to respond to the repeated requests from those IP addresses.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Without putting something on another device down the line towards the ISP I'm not sure what to do in terms of the ASA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;My log line for the scans look like this:&lt;/DIV&gt;
&lt;DIV&gt;[ Scanning] drop rate-1 exceeded. Current burst rate is 1 per second, max configured rate is 10; Current average rate is 7 per second, max configured rate is 5; Cumulative total count is 4627&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Thanks,&lt;/DIV&gt;
&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2018 15:18:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-scans-attacks-on-cisco-asa-slowing-down-internet/m-p/3381908#M958642</guid>
      <dc:creator>mvelatln</dc:creator>
      <dc:date>2018-05-11T15:18:32Z</dc:date>
    </item>
  </channel>
</rss>

