cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
387
Views
0
Helpful
1
Replies

Shunning or blocking IP that are scanning

james.biddle1
Level 1
Level 1

We are trying to fine tune the shunning or blocking of IP addresses that are scanning etc., and seeing that they are allow to scan for some time before being blocked/shunned. I see the settings below but would like some further help with  making sure I tweak the right setting. We just need to be sure they are blocked a little quicker. 

I found the link and settings below as well:

These are not from my ASA, just a shot of the path I am on... If I can adjust the setting in the GUI above that would be great, but looks like I may need to hit the command line to fine tune this? Thanks for any help!

threat-detection rate dos-drop rate-interval 600 average-rate 100 burst-rate 400
threat-detection rate dos-drop rate-interval 3600 average-rate 80 burst-rate 320
threat-detection rate bad-packet-drop rate-interval 600 average-rate 100 burst-rate 400
threat-detection rate bad-packet-drop rate-interval 3600 average-rate 80 burst-rate 320
threat-detection rate acl-drop rate-interval 600 average-rate 400 burst-rate 800
threat-detection rate acl-drop rate-interval 3600 average-rate 320 burst-rate 640
threat-detection rate conn-limit-drop rate-interval 600 average-rate 100 burst-rate 400
threat-detection rate conn-limit-drop rate-interval 3600 average-rate 80 burst-rate 320
threat-detection rate icmp-drop rate-interval 600 average-rate 100 burst-rate 400
threat-detection rate icmp-drop rate-interval 3600 average-rate 80 burst-rate 320
threat-detection rate scanning-threat rate-interval 600 average-rate 5 burst-rate 10
threat-detection rate scanning-threat rate-interval 3600 average-rate 4 burst-rate 8
threat-detection rate syn-attack rate-interval 600 average-rate 100 burst-rate 200
threat-detection rate syn-attack rate-interval 3600 average-rate 80 burst-rate 160
threat-detection rate fw-drop rate-interval 600 average-rate 400 burst-rate 1600
threat-detection rate fw-drop rate-interval 3600 average-rate 320 burst-rate 1280
threat-detection rate inspect-drop rate-interval 600 average-rate 400 burst-rate 1600
threat-detection rate inspect-drop rate-interval 3600 average-rate 320 burst-rate 1280
threat-detection rate interface-drop rate-interval 600 average-rate 2000 burst-rate 8000
threat-detection rate interface-drop rate-interval 3600 average-rate 1600 burst-rate 6400
1 Reply 1

Aditya Ganjoo
Cisco Employee
Cisco Employee

Hi James,

The default rates can be viewed with the show run all threat-detection command.

In order to tune these rates with custom values, simply reconfigure the threat-detection rate command for the appropriate threat category.

You can also use ASDM for the same, please check this link:

http://www.cisco.com/c/en/us/td/docs/security/asa/asa84/asdm64/configuration_guide/asdm_64_config/protect_threat.pdf

After doing the changes use the show run all threat-detection command to check if the changes have been reflected.

Regards,

Aditya

Please rate helpful posts.

Review Cisco Networking for a $25 gift card