cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

225
Views
0
Helpful
2
Replies
Highlighted
Beginner

High Currennt Connection

Hi,

I have cisco asa firewall.

If my current connection reach 250k my network will go down.

Any method to avoid this issue from happen?

How to find the root cause?

 

 

2 REPLIES 2
Highlighted
Rising star

In my case happens during attacks.

I use cisco ASDM to see connections or show connections using CLI.

I use these tools in order to find repeated entries.

Sometimes I foud a lot of connections from a single IP.

In others cases I found a lot of connections from many IPs destinated to the same port.

In this case I use ACL to block unwanted traffic.

 

Enable also IP audit feature in order to block some well know attacks.

 

Regards.

Highlighted
Beginner

Yes , you will experience a drop. Scenario1 : For Data you may not experience the drop Scenario2 : For voice there will be a intermittent drop. Scenario3 : Every time you have to clear the connection when it reaches the maximum connection Solution:- 1. To limit the connection on the firewall using the ACL and remove unnecessary traffic hitting the firewall. 2. Upgrade the Firewall for more connection support 3. Configure policy to shorter the timeout for the embryonic connection.
Content for Community-Ad