ā06-24-2011 07:59 AM - edited ā03-11-2019 01:50 PM
Hello.
Recently, I've been having significant problems with denial of service on our ASA-5510. Two IP addresses in particular attack my ASA regularly. What kind of rule do I need to create to deny these IP's access to my firewall?
Thanks!
Sent from Cisco Technical Support iPhone App
ā06-24-2011 08:09 AM
What type of attack?
ā06-24-2011 08:46 AM
Either a Scan or SYN attack. But the IP's in question are generating significant inbound traffic. They are listed in top 10 sources pie of my ASDM GUI.
Sent from Cisco Technical Support iPhone App
ā06-24-2011 08:50 AM
Hey Josh,
If you don't want any connection to estaiblish from two known IP addresses, you may go ahead and "shun" them. The command to do this will look like:
hostname# shun
Hope this helps!
Regards,
Aditya
ā06-24-2011 11:05 AM
Since the attack has already taken place. If you are not allowing these IPs ASA will be blocking them anyways. The best course of action will be to have it blocked upstream and if upstream is your service provider then talk to provider to have the IPs blocked on upstream.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide