cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
396
Views
0
Helpful
3
Replies

DOS attack on IOS Firewall

echuang
Level 1
Level 1

Is there a way to stop DOS attach on my web server that is behind a IOS Firewall. I see a lot on unwanted automated HTTP connection on my web server.

3 Replies 3

athompson
Level 1
Level 1

If the IP address that it's coming from doesn't change, you can add an ACL to the Firewall denying all traffic from that address range.

If they're taking up a lot of your bandwidth to your ISP, you can also talk to the ISP and have them do filtering on their end. Most ISP's will do this if you have a dedicated business-class connection I think.

daftary
Level 1
Level 1

if u have ios firewall configured for inbound traffic destined for your web server, then u can tweak the following config cmds to prevent dos:

ip inspect max-incomplete high

ip inspect max-incomplete low

ip inspect one-minute high

ip inspect one-minite low

ip inspect tcp max-incomplete host