05-14-2005 09:05 AM - edited 03-03-2019 09:34 AM
Hi,
One of our routers was detected being vulnerable to SYN-FIN flood attack. Will this be cured by disabling "ip http server" on the router?
-Sai.
05-15-2005 03:52 AM
not realy as it will activly "fin"the syn.
You should use an accesslist to the management destination to prevent this.
05-15-2005 07:39 AM
Hi,
is there any specific ports I should block??
i did not understand ur message.
-Sai.
05-17-2005 12:59 AM
yep to the vunrable device you should block evry port witch is not used.
deny ip any
in front of this statement you can put the permits (telnett example) witch are used for management.
permit tcp any
end the acl by permitting all allowed traffic through.
But it would be highly recommended to use a device / software witch is not vunrable as these filtest do cost performance.
What kind of device are we talking about in what situation ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide