08-22-2013 01:31 PM - edited 03-11-2019 07:29 PM
Hello guys,
I have an ASA 5550 for 3 years, it's been working great. I was wondering how do I detect if I'm under DDOS/SYN attack from my ASA (ASDM or CLI)? How to mitigate the attack? Thanks.
08-23-2013 01:48 AM
ASA has basic threat detection features (ASDM -> Config -> Firewall -> Threat Detection) where you can configure it (SYN attacks). DDOS is not very specific because there are many variants of it, currently most of it are DNS attacks
Michael
Please rate all helpful posts
08-23-2013 07:37 AM
I have those enabled now. I've heard a lot about DNS attacks but what exactly ASA can do to migitate it? if not what can I do/buy (I've heard of IPS module for ASA) to migitate it if it happens? Thanks and have a good Friday!
08-23-2013 08:18 AM
08-23-2013 03:42 PM
There are a lot of companies that specialize in Netflow products speficially tailored towards DDOS detection.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide