cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2831
Views
0
Helpful
4
Replies

Detect DDOS attack?

tinhnho123
Level 2
Level 2

Hello guys,

I have an ASA 5550 for 3 years, it's been working great. I was wondering how do I detect if I'm under DDOS/SYN attack from my ASA (ASDM or CLI)? How to mitigate the attack? Thanks.

4 Replies 4

Michael Muenz
Level 5
Level 5

ASA has basic threat detection features (ASDM -> Config -> Firewall -> Threat Detection) where you can configure it (SYN attacks). DDOS is not very specific because there are many variants of it, currently most of it are DNS attacks

Michael

Please rate all helpful posts

Michael Please rate all helpful posts

I have those enabled now. I've heard a lot about DNS attacks but what exactly ASA can do to migitate it? if not what can I do/buy (I've heard of IPS module for ASA) to migitate it if it happens? Thanks and have a good Friday!

http://www.prolexic.com/

Michael

Please rate all helpful posts

Michael Please rate all helpful posts

Anthony.Herman
Level 1
Level 1

There are a lot of companies that specialize in Netflow products speficially tailored towards DDOS detection.

Review Cisco Networking for a $25 gift card