03-12-2011 05:58 PM - edited 03-11-2019 01:05 PM
Hi there,
One of my customers are facing a DDoS attack on their email servers. I am in charge of ASA config.
Here is what I have done so far and it was not very effective:
tcp-map LimitEmail
check-retransmission
checksum-verification
exceed-mss drop
reserved-bits drop
syn-data drop
tcp-options window-scale clear
window-variation drop-connection
03-13-2011 04:57 AM
Do you have ESMTP inspection enabled as well? This can help in preventing some forms of attacks, See below a config reference:
http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/inspect_basic.html#wp1542178
03-13-2011 06:13 AM
Hi Sean,
Thanks for the reply. Yes, it is on.
I could not find any class-map type inspect for SMTP/POP3/IMAP. ASA 8.2(1) has those for DNS, HTTP, IM, etc...
Rgs,
Marcelo Pinheiro
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide