cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
382
Views
5
Helpful
1
Replies

TCP vulnerability?

tato386
Level 6
Level 6

Our 2600 running 12.2.8T1 has been giving us problems lately. There are two symptoms we are seeing. One is having the CPU pegged at 99% usage with no traffic going thru the router. The second is that we are seeing packets being dropped during communication to certian web sites but not others. In both cases the problems are fixed by rebooting the router. In light of the TCP vulnerabilities announced last week could we be seeing some of this on our router? We are not a big high-profile place so I wouldn't expect any DOS or hacking against us but I guess that you never know. Is our router vulnerable to the TCp exploits?

Thanks,

Diego

1 Reply 1

Harold Ritter
Level 12
Level 12

Unless you are running BGP and are receiving full Internet routing table, you are very unlikely to run into this issue. Routers are vulnerable only for TCP sessions terminating on the router itself not session going through it.

You should do a "sh proc cpu" when the CPU on the router hits 99% to see which process is chewing up the CPU cycles.

Hope this help,

Harold Ritter
Sr Technical Leader
CCIE 4168 (R&S, SP)
harold@cisco.com
México móvil: +52 1 55 8312 4915
Cisco México
Paseo de la Reforma 222
Piso 19
Cuauhtémoc, Juárez
Ciudad de México, 06600
México

Review Cisco Networking for a $25 gift card