<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Deny IP due to Land Attack same My IP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/deny-ip-due-to-land-attack-same-my-ip/m-p/3361671#M963253</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I keep receiving log messages on ASA 5545X like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;TD&gt;Apr 06 2018&lt;/TD&gt;
&lt;TD&gt;07:47:57&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;19.19.20.4&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;19.19.20.4&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;Deny IP due to Land Attack from 19.19.20.4 to 19.19.20.4&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is for server -&amp;nbsp; IP which is 1-to-1 NAT&lt;/P&gt;
&lt;P&gt;10.1.4.4 -&amp;gt;19.19.20.4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CONFIG:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;object network 19.19.20.4-10.1.4.4&lt;/P&gt;
&lt;P class="p1"&gt;nat (inside,outside) static 19.19.20.4 dns&lt;/P&gt;
&lt;P class="p1"&gt;host 10.1.4.4&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;and same happens&amp;nbsp;with this log:&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN&gt;This is for&amp;nbsp;local host/network 10.44.0.0&amp;nbsp; -&amp;nbsp; IP which is 1-to-many NAT&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;TD&gt;Apr 06 2018&lt;/TD&gt;
&lt;TD&gt;07:48:23&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;19.19.20.244&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;19.19.20.244&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;Deny IP due to Land Attack from 19.19.20.244 to 19.19.20.244&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;CONFIG:&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;object network 19.19.20.244-10.44.0.0&lt;/P&gt;
&lt;P class="p1"&gt;nat (inside,outside) dynamic 19.19.20.244&lt;/P&gt;
&lt;P class="p1"&gt;subnet 10.44.0.0 255.255.0.0&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;Is something&amp;nbsp;with NAT config&amp;nbsp;wrong?&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;Best regards,&lt;/P&gt;
&lt;P class="p1"&gt;Ivan&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:36:23 GMT</pubDate>
    <dc:creator>Ivan Marinovic</dc:creator>
    <dc:date>2020-02-21T15:36:23Z</dc:date>
    <item>
      <title>Deny IP due to Land Attack same My IP</title>
      <link>https://community.cisco.com/t5/network-security/deny-ip-due-to-land-attack-same-my-ip/m-p/3361671#M963253</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I keep receiving log messages on ASA 5545X like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;TD&gt;Apr 06 2018&lt;/TD&gt;
&lt;TD&gt;07:47:57&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;19.19.20.4&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;19.19.20.4&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;Deny IP due to Land Attack from 19.19.20.4 to 19.19.20.4&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is for server -&amp;nbsp; IP which is 1-to-1 NAT&lt;/P&gt;
&lt;P&gt;10.1.4.4 -&amp;gt;19.19.20.4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CONFIG:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;object network 19.19.20.4-10.1.4.4&lt;/P&gt;
&lt;P class="p1"&gt;nat (inside,outside) static 19.19.20.4 dns&lt;/P&gt;
&lt;P class="p1"&gt;host 10.1.4.4&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;and same happens&amp;nbsp;with this log:&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN&gt;This is for&amp;nbsp;local host/network 10.44.0.0&amp;nbsp; -&amp;nbsp; IP which is 1-to-many NAT&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;TD&gt;Apr 06 2018&lt;/TD&gt;
&lt;TD&gt;07:48:23&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;19.19.20.244&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;19.19.20.244&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;Deny IP due to Land Attack from 19.19.20.244 to 19.19.20.244&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;CONFIG:&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;object network 19.19.20.244-10.44.0.0&lt;/P&gt;
&lt;P class="p1"&gt;nat (inside,outside) dynamic 19.19.20.244&lt;/P&gt;
&lt;P class="p1"&gt;subnet 10.44.0.0 255.255.0.0&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;Is something&amp;nbsp;with NAT config&amp;nbsp;wrong?&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;Best regards,&lt;/P&gt;
&lt;P class="p1"&gt;Ivan&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:36:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-ip-due-to-land-attack-same-my-ip/m-p/3361671#M963253</guid>
      <dc:creator>Ivan Marinovic</dc:creator>
      <dc:date>2020-02-21T15:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: Deny IP due to Land Attack same My IP</title>
      <link>https://community.cisco.com/t5/network-security/deny-ip-due-to-land-attack-same-my-ip/m-p/3361727#M963254</link>
      <description>&lt;P&gt;Hi Ivan,&lt;/P&gt;
&lt;P&gt;Land Attack simply means the packets have the same source ip and destination ip, in your case it seems to be&amp;nbsp;&lt;SPAN&gt;19.19.20.4 and&amp;nbsp;19.19.20.244.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Is it possible that&amp;nbsp;&lt;SPAN&gt;10.1.4.4 is sending packets to&amp;nbsp;19.19.20.4, or&amp;nbsp;10.44.0.0/24 to&amp;nbsp;19.19.20.244 ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can set up some captures to find out.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If yes configure identity nat for that specific destination.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Bogdan&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 09:58:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-ip-due-to-land-attack-same-my-ip/m-p/3361727#M963254</guid>
      <dc:creator>Bogdan Nita</dc:creator>
      <dc:date>2018-04-06T09:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Deny IP due to Land Attack same My IP</title>
      <link>https://community.cisco.com/t5/network-security/deny-ip-due-to-land-attack-same-my-ip/m-p/3361943#M963255</link>
      <description>Maybe create a nonat rule to packets on the same private network?</description>
      <pubDate>Fri, 06 Apr 2018 17:05:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-ip-due-to-land-attack-same-my-ip/m-p/3361943#M963255</guid>
      <dc:creator>mplaksin0</dc:creator>
      <dc:date>2018-04-06T17:05:30Z</dc:date>
    </item>
  </channel>
</rss>

