cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4525
Views
1
Helpful
2
Replies

Recommended values for synflood and rate limiting

JP_Berlin
Cisco Employee
Cisco Employee

Hi community,

I have two questions regarding the ISE CLI commands synflood-limit and rate-limit:

  1. I do understand the use case for synflood-limit since a high number of TCP-SYN is a clear indication for a malicious attack. But what about the use case for rate-limit? ISE inter-node communication? Communication with integrated 3rd party devices (for example through pxgrid)? Or even access to the ISE portals (Guest, Sponsor...)? I would appreciate if someone shed some light on this.
  2. And finally I am looking for recommended values for the synflood-limit and rate-limit commands (in terms of packets per second). In other words: are there any guidelines on how to avoid an impact on ISE operations.

Cheers!

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

Such settings could impact authentication TPS; especially EAP-TLS. Please use them with cautions.

The command synflood-limit takes only a numeric value as the argument so it applies to all TCP attempts. A similar command "conn-limit" takes ip and port arguments so give us more choices if we are to implement sync flood protection on TCP connections. The other command "rate-limit" also take ip and port arguments but it applies to all TCP/UDP/ICMP.

View solution in original post

2 Replies 2

hslai
Cisco Employee
Cisco Employee

Such settings could impact authentication TPS; especially EAP-TLS. Please use them with cautions.

The command synflood-limit takes only a numeric value as the argument so it applies to all TCP attempts. A similar command "conn-limit" takes ip and port arguments so give us more choices if we are to implement sync flood protection on TCP connections. The other command "rate-limit" also take ip and port arguments but it applies to all TCP/UDP/ICMP.

Hello, hslai

 

I would like to know if maybe you know what is it the recommended rate for configuring with the command "rate-limit" for TCP/UDP/ICMP.  Right now I'm hardening an ISE deployment, and I've been following this guide https://community.cisco.com/t5/security-documents/ise-security-best-practices-hardening/ta-p/3640651 but I don't know what value the rate limit has to take. 

 

Thank you so much in advance.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: