03-19-2018 01:23 AM - edited 02-21-2020 07:31 AM
dispatch unit process using almost 100% CPU; frequency of the incident is 2 hours; FW get hanged and after removing the cable from FW, it get stable; again same after 2 hours;
hardware:- asa 5520
topology:-
SW 2960----------FW5520_______asr1002
tcp connection sudennely increases to 5K, under normal condition it was less than 100;
Kindly share resolution steps;
03-19-2018 02:16 AM
03-19-2018 03:23 AM
yes, as per my observation its a dos attack; few host(like 10.x.y.20) establishing tcp connection with 10.x.y.255 over port number 445; after scan that host 20 virus found; i want to isolate this;
03-19-2018 04:28 AM
03-19-2018 04:46 AM
pls share configuration;
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide