01-14-2011 11:21 PM - edited 03-11-2019 12:35 PM
Hello
How to overcome "Denial of DOS Attack" on ASA 5510, any recommendations or best practises
Considering the public ip is not same all the time.
thanks
Saquib
01-15-2011 12:03 AM
I'll assume you don't have the CSC-AIP module, no?
Maybe the 'ip audit' and 'threat-detection' commands can help.
01-15-2011 07:00 AM
You can limit per-client max and enable per-client-embryonic-conn-max but, the best place to stop this is before it reaches the outside interface.
Engage your ISP.
Here is the link for per-client-max and embryonic-max:
http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/s1.html#wp1424045
-KS
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide