cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
434
Views
5
Helpful
1
Replies

TCP vulnerability?

tato386
Level 6
Level 6

Our 2600 running 12.2.8T1 has been giving us problems lately. There are two symptoms we are seeing. One is having the CPU pegged at 99% usage with no traffic going thru the router. The second is that we are seeing packets being dropped during communication to certian web sites but not others. In both cases the problems are fixed by rebooting the router. In light of the TCP vulnerabilities announced last week could we be seeing some of this on our router? We are not a big high-profile place so I wouldn't expect any DOS or hacking against us but I guess that you never know. Is our router vulnerable to the TCp exploits?

Thanks,

Diego

1 Reply 1

Harold Ritter
Spotlight
Spotlight

Unless you are running BGP and are receiving full Internet routing table, you are very unlikely to run into this issue. Routers are vulnerable only for TCP sessions terminating on the router itself not session going through it.

You should do a "sh proc cpu" when the CPU on the router hits 99% to see which process is chewing up the CPU cycles.

Hope this help,

Regards,
Harold Ritter, CCIE #4168 (EI, SP)