03-18-2011 02:47 AM - edited 03-11-2019 01:08 PM
Hi Experts,
Recently i implemented Kiwisyslog server in Office. from the logs it was clear that someone was trying to access our network. It was showing TCP connection denied from the src IP address<a public IP>. When i checked the IP address, that IP address was from england, also there was multiple IP address (4 or 5) from different location. and the priority level of all the message is warning. I am using ASA5505. Is it normal in everywhere???
If there any solution for this??? please reply....ASAP urgent.......
Thanks&Regards
Vipin Raj R.C
Solved! Go to Solution.
03-18-2011 03:12 AM
Hi,
There might be illegitimate attempts to gain access from outside. We should be fine until ASA is able to deny these attempts AND the rate of such attempts are not so high as to 'kill' the ASA (like DoS).
Unless these packets are blocked somewhere on the outside, they will reach the ASA. The ASA has to perform the security check and ultimately deny them. This is fine as long as such packets are not very frequent. But if they shoot up then it would be better to block them at ISP level or on outside router.
Paps
03-18-2011 03:12 AM
Hi,
There might be illegitimate attempts to gain access from outside. We should be fine until ASA is able to deny these attempts AND the rate of such attempts are not so high as to 'kill' the ASA (like DoS).
Unless these packets are blocked somewhere on the outside, they will reach the ASA. The ASA has to perform the security check and ultimately deny them. This is fine as long as such packets are not very frequent. But if they shoot up then it would be better to block them at ISP level or on outside router.
Paps
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide