cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1702
Views
0
Helpful
1
Replies

[Scanning] drop rate-1 exceeded - causing PIX to drop

amarula115
Level 1
Level 1

I am getting the following message in PIX-515 log file:

[ Scanning] drop rate-1 exceeded. Current burst rate is 10 per second, max configured rate is 10; Current average rate is 2 per second, max configured rate is 5; Cumulative total count is 1283

Pix is running Security Appliance Software Version 8.0(2)

I found on Cisco Web explanation that this is a "scanning attack" but I have no clue how to troubleshoot it. Anybody have experience with this kind of situation?

This is causing PIX to drop connection between my serveres and application need to be restarted manually which is causing company wide havoc.

Any help appreciated

1 Reply 1

carenas123
Level 5
Level 5

The specified object in the system log message has exceeded the specified burst threshold rate or average threshold rate. The object can be drop activity of a host, TCP/UDP port, IP protocol, or various drops due to potential attacks. It indicates the system is under potential attack.

Review Cisco Networking for a $25 gift card