07-10-2008 11:24 PM - edited 03-11-2019 06:12 AM
Hi,
We have Cisco ASA 5520.Nowadays we are getting one problem that is TCP/UDP connection fluctuating continuously.
I am checking in ASDM, suppose now showing total no. of connection 50 within 2 sec it's reaching 3000 and again come back to normal.
It's happening continuously.
What might be the reason for that? Pls assist too resolve this issue.
Thanx,
somnath
07-11-2008 06:18 AM
probably you have worms...
try to find suspicious connections
"sh conn"
[Pls RATE if HELPS]
07-11-2008 06:26 AM
Can you put sniffer and check which host or application does that?
Thanks,
Dharmesh Purohit
07-11-2008 09:10 PM
If the connection spikes up to 3000 and then drops sharply 30 seconds later, that is most likely a flood of TCP connection (DoS Attack) that result in short lived, half-open TCP conns. Please gather SYSLOGs during the spikes and provide a sample for us to take a look at.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide