Solved

CSS 11501 DOS attack white list

Posted on 2008-10-13
4
851 Views
Last Modified: 2013-12-09
Hello..... is it possible to white list a network or host address? I have a situation where a NAT'ed ip is being blocked possibly because of the number of connections coming through. Any input will be appreciated. Thanks.
0
Comment
Question by:cavacamite
  • 2
  • 2
4 Comments
 
LVL 32

Expert Comment

by:harbor235
ID: 22707897


CSS perfroms NAT, it is also a content service device, load balancer, etc .... The CSS doe snot handle spam or deal with DOS attacks.

harbor235 ;}
0
 

Author Comment

by:cavacamite
ID: 22708014
Thanks. See the DOS output below. The source address is the one experiencing problems accessing the destination ip. The CSS isn't configured to block anything. Could there be any default values on the CSS causing the problem?
DOS Attack Event  1:
First Attack: 10/13/2008 15:47:56
Last Attack:  10/13/2008 16:09:01
Source Address: A.B.C.D  Destination Address: A.B.R.T
Event Type: SYN Attack Total Attacks: 402

0
 
LVL 32

Accepted Solution

by:
harbor235 earned 500 total points
ID: 22711272


The DOS feature on the CSS is informational only, it provides statistics on potential attacks and allows you to send SNMP traps to alrt you, it doe snot perfrom DOS mitigation. You can accumulate statistics and you can also reset those statistics for monitoring purposes. I did not this feature existed until yooumade me look at it, thanx

http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/css11500series/v8.20/configuration/administration/guide/SNMP.html#wp1051871

harbor235 ;}
0
 

Author Comment

by:cavacamite
ID: 22712426
Thanks very much for your help. That means back to troubleshooting the issue.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Norton antivirus 11 94
Spam mails from a compromised internal computer 5 139
setting up spf for our domain 5 234
Exchange 2010 Email server black listed 14 79
When replacing some switches recently I started playing with the idea of having admins authenticate with their domain accounts instead of having local users on all switches all over the place. Since I allready had an w2k8R2 NPS running for my acc…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

713 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question