cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
631
Views
0
Helpful
1
Replies

Query regarding DDOS Attacks

mukundh86
Level 1
Level 1

Hello all,

I have attached a network diagram with this post. It shows a Cisco Catalyst 4500 to which we have connected our Datacenter customers an also our Back office LAN.

What happened was that there was a DDOS attack towards Customer XYZ. It brought down the ASA 5510 and the IPS installed in it. It also affected our Backoffice with extremely slow internet, but the rest of the datacenter customers had no issues. I had to administratively shut down the link towards XYZ to get everything back to normal. What confuses me is how would this DDOS affect only the BAckoffice and not the rest of the datacenter. I checked the IPS logs and it says "RFC 1918 addresses seen" signature fired the most.

1 Reply 1

mukundh86
Level 1
Level 1

Attached is network diagram

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card