Solved

Cisco ASA5510 - LAND ATTACK

Posted on 2013-05-14
6
1,410 Views
Last Modified: 2013-05-20
I want to know if there is anything else I should be doing to mitigate against a Denial of Service Attack that I am currently experiencing.  I have a customer whose network was very slow.  I got into the ASA5510 and saw it was being hammered.  Over 50,000 connections to some of my static NAT's.  I was losing 2 out of every 4 pings to the ASA because it was so overloaded.  I set a per connection client limit on the addresses being targeting on my network, which seems to have  mitigated the problem, but now I'm constantly seeing messages that that per-client connection has been exceeded, as well as a message stating "Deny IP due to Land Attack from x.x.x.136 to x.x.x.136."  Source and destination are the same.  I called my ISP, but I got an email stating that it may take them awhile to investigate due to the amount of abuse emails they receive.  Is there anything else I can do to stop the attack?
0
Comment
Question by:denver218
6 Comments
 
LVL 11

Accepted Solution

by:
rharland2009 earned 167 total points
Comment Utility
https://supportforums.cisco.com/docs/DOC-14318

This is a decent rundown of why you may be seeing these.
Is the IP address mentioned in the Land Attack one of yours, or one you're not familiar with?
0
 
LVL 4

Author Comment

by:denver218
Comment Utility
It's one of my Addresses in my public IP block
0
 
LVL 11

Assisted Solution

by:naderz
naderz earned 167 total points
Comment Utility
Do you have IPS enabled? If so, try disabling that and test. You may be experiencing false positives.
0
Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

 
LVL 28

Assisted Solution

by:asavener
asavener earned 166 total points
Comment Utility
If you access any of your internal/published resources via their public IP addresses, then the LAND attack notifications are likely due to that.
0
 
LVL 4

Author Comment

by:denver218
Comment Utility
Thanks for all your comments.  It was DoS attack, the ASA was doing its job blocking all the traffic, but I had to report it to the ISP so they could put an ACL on their side to stop the traffic.  It was coming in at such high rates, that I had to get the ISP involved.  The ISP saw it right away and was able to take care of it.  Thanks.
0
 
LVL 4

Author Closing Comment

by:denver218
Comment Utility
Thanks.
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Phishing is at the top of most security top 10 efforts you should be pursuing in 2016 and beyond. If you don't have phishing incorporated into your Security Awareness Program yet, now is the time. Phishers, and the scams they use, are only going to …
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now