Advertisement

07.16.2008 at 02:42PM PDT, ID: 23571419 | Points: 500
[x]
Attachment Details

ASA 5510 - Help blocking TCP SYN packets

Asked by Aaron_J_Marshall in Enterprise Firewalls

Tags: Cisco, ASA, 5510

Can anyone help me to block all TCP SYN packets to a destination port on an ASA 5510?


(from our security scanner)
--
TCP Source Port Pass Firewall         
 
THREAT:
Your firewall policy seems to let TCP packets with a specific source port pass through.

IMPACT:
Some types of requests can pass through the firewall. The port number listed in the results section of this vulnerability report is the source port that unauthorized users can use to bypass your firewall.

SOLUTION:
Make sure that all your filtering rules are correct and strict enough. If the firewall intends to deny TCP connections to a specific port, it should be configured to block all TCP SYN packets going to this port, regardless of the source port.

COMPLIANCE:
Not Applicable

RESULTS:
The host responded 4 times to 4 TCP SYN probes sent to destination port xx using source port 80.
However, it did not respond at all to 4 TCP SYN probes sent to the same destination port using a
random source port.

Start Free Trial
[+][-]08.04.2008 at 07:23PM PDT, ID: 22157652

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628