Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Checking for half open connections

Posted on 2004-08-08
8
Medium Priority
?
2,162 Views
Last Modified: 2007-12-19
Hi,

This is really an extension of my previous post. I managed to track down the issue behind high cpu utilization, which was indeed caused by a worm. The worm caused a lot of hosts to open and terminate connections to our servers, leaving them in the TIME_WAIT state. Some hosts had opened thousands of connections to the servers.

How do I track down these half-closed connections on the firewall? A "show conn " gives out a lot of detail. What do I need to look for?

Second question.

While I was trying to track down the infected hosts using a sniffer, a vendor suggested that I use the MSFC on the core switch as a source and filter it on the specific VLAN. How is this different from port mirroring?

The commands I used were

MSFC sniffing ----> set span (msfc) (destination port) filter (vlan_number)
Port sniffing   ----> set span (vlan_number) (destination port)

Each of these methods threw up a completely different set of statistics. What is the difference?
0
Comment
Question by:fullerms
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
8 Comments
 
LVL 51

Accepted Solution

by:
ahoffmann earned 80 total points
ID: 11750291
any statefull inspection firewall should manage this automatically, or better give some options like timeouts to close them.
On the other side, it depends on the implementation of your TCP/IP stack on the effected server how it handles such sockets, most likely the OS provides a timeout for such sockets in TIME_WAIT state too.
0
 
LVL 6

Author Comment

by:fullerms
ID: 11750479
Agreed. The firewall does have timeouts values for half open connections.

My question is, how do I check for half open connections on the firewall? At any given point of time, the firewall is handling 3 times the normal number of connections. We need information on half open connections to track down the offending IPs. How do I go about this?
0
 
LVL 51

Expert Comment

by:ahoffmann
ID: 11751154
> ..  how do I check for half open connections on the firewall?
read your docs of the firewall. There is no general answer, it's specific to your firewall.
0
Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.

 
LVL 6

Author Comment

by:fullerms
ID: 11751563
The firewall is a Cisco Pix v 6.3(3).
0
 
LVL 6

Author Comment

by:fullerms
ID: 15898269
I wouldn't like to be called a miser, but I feel that a refund would be more appropriate. I did not get the answer that could have helped me.
0
 
LVL 20

Expert Comment

by:Venabili
ID: 15898337
You were pointed in the right direction what to read. You never said if you checked your documentation...
0

Featured Post

2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
Visualize your data even better in Access queries. Given a date and a value, this lesson shows how to compare that value with the previous value, calculate the difference, and display a circle if the value is the same, an up triangle if it increased…
Want to learn how to record your desktop screen without having to use an outside camera. Click on this video and learn how to use the cool google extension called "Screencastify"! Step 1: Open a new google tab Step 2: Go to the left hand upper corn…
Suggested Courses

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question