cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
883
Views
0
Helpful
3
Replies

IPS reports

Reshma Raje
Level 1
Level 1

IPS report shows victim IP address on which the attack was launched, how is external attacker able to attack specific private IP addresses in a huge infrastructure?

3 Replies 3

Oliver Kaiser
Level 7
Level 7

The connection could be established from the infected client to a C&C server. If the attack is initiated from the WAN to a server on-site you might see the private ip address because NAT is done before traffic is sent to the sfr module on Cisco ASA (or NAT is done on a router before your ips sensor).

Let me know if this answers your question.

Thank you for your reply but my query is, attack from external IP on internal IP where the IPS report publishes internal IP on which there was an attack tried by the external IP...

My first sentence should answer your question. A host in your network connects to a malicious Server in the Internet... A host that is not directly reachable from the Internet due to firewall rules and/or NAT can still be attacked if it opens up a session to an attacker, which can use this session to attack said client.

Review Cisco Networking for a $25 gift card