I have attached a network diagram with this post. It shows a Cisco Catalyst 4500 to which we have connected our Datacenter customers an also our Back office LAN.
What happened was that there was a DDOS attack towards Customer XYZ. It brought down the ASA 5510 and the IPS installed in it. It also affected our Backoffice with extremely slow internet, but the rest of the datacenter customers had no issues. I had to administratively shut down the link towards XYZ to get everything back to normal. What confuses me is how would this DDOS affect only the BAckoffice and not the rest of the datacenter. I checked the IPS logs and it says "RFC 1918 addresses seen" signature fired the most.