cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
948
Views
5
Helpful
2
Replies

syn flood signature 6009/0 actions

MJonkers
Level 1
Level 1

Hi is there an option when this signature fires to block the attacker or this attack and not just log the attack? I tried to set the actions but the log says no action taken.

2 Replies 2

Maykol Rojas
Cisco Employee
Cisco Employee

Hello;

 

Yes, when you set the actions, you can select deny atacker inline. Make sure thou, that there are no Event action filters and that the IPS is inline between the hosts.

 

Mike.

Mike

Hi Thx for the answer. I did add the action but no luck or does it nog log this action? The traffic hits the client inside the network so the ips does not block.

 

Event ID1397033001306299442
Severityhigh
Host IDIPS-DEB1-1
Application NamesensorApp
Event Time01/06/2015 10:18:30
Sensor Local Time01/06/2015 09:18:30
Signature ID6009
Signature Sub-ID0
Signature NameSYN Flood DOS
Signature VersionS593
Signature DetailsSYN Flood DOS
Interface Groupvs1
VLAN ID0
Interfacete7_0
Attacker IPxx.xx.xxx.84
Protocoltcp
Attacker Port1321
Attacker LocalityOUT
Target IPyy.yy.yy.102
Target Port80
Target LocalityOUT
Target OSunknown unknown (relevant)
Actions 
Risk RatingTVR=medium ARR=relevant
Risk Rating Value95
Threat Rating95
Reputation 
Context Data 
Packet Data 
Event Summary0
Initial Alert 
Summary Type 
Final Alert 
Event StatusNew
Event Notes 
  
Review Cisco Networking for a $25 gift card