Solved

Cisco ASA 5510 DMZ attack issues

Posted on 2010-09-21
7
939 Views
Last Modified: 2013-11-16
We are having problems with attacks on our web servers.
We have an ASA 5510 and it reports 120+ scanning attacks and 60+ SYN attacks.
When these are higher than 5 the web servers go extremely slow and do not respons.
This is happening for longer periods of time now.
Basic threat detection is enabled, scanning threat detection is enabled and Shun Hosts.

Can anyone help?


Thanks
0
Comment
Question by:CTEC
  • 4
  • 3
7 Comments
 
LVL 17

Accepted Solution

by:
Kvistofta earned 500 total points
ID: 33726203
Do you have any max conns or embrionics-limit defined in the static for your web server?

http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/s8.html#wp1512466

By setting a limit for this you make your firewall protect your web server from syn attacs.

/Kvistofta
0
 

Author Comment

by:CTEC
ID: 33726231
i have embrionics-limit set to 25 on the web servers
0
 

Author Comment

by:CTEC
ID: 33726258
static (DMZ,outside) ***.***.***.*** ***.***.***.*** netmask 255.255.255.255 dns tcp 0 25
0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 
LVL 17

Expert Comment

by:Kvistofta
ID: 33726544
And you are still getting 60+ half-open connections to the web-server???

/Kvistofta
0
 

Author Comment

by:CTEC
ID: 33726980
yes, currently ASDM reports under firewall dashboard:

Scanning attacks: 122
SYN attacks: 85
0
 
LVL 17

Expert Comment

by:Kvistofta
ID: 33727034
Ok. But do you have any performance issues on your web server? What you see just indicates that the firewall does what it is built to do. If you do not want to see the firewall identifying and/or blocking attacks you need to protect it with another firewall infront of it. .-)

/Kvistofta
0
 

Author Comment

by:CTEC
ID: 33727150
when the firewall reports high scanning attacks and SYN attacks the webservers will not respond to http requests, if i stop inbound traffic the webservers work normally
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

There are some basic methods for preventing attacks on, hacking of and unauthorized access to a network -- maybe not completely, but up to a certain level. Start with a well-reputed firewall and unified threat management (UTM) system -- a gateway…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…
Many functions in Excel can make decisions. The most simple of these is the IF function: it returns a value depending on whether a condition you describe is true or false. Once you get the hang of using the IF function, you will find it easier to us…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now