Solved

DoS attack

Posted on 2014-03-25
3
443 Views
Last Modified: 2014-04-01
Is it possible to block certain foreign countries altogether to prevent a DoS attack, also what else can be done to prevent a DoS attack on a public facing 3845 Cisco ISR?
0
Comment
Question by:dcawood
3 Comments
 
LVL 3

Accepted Solution

by:
englanddg earned 167 total points
Comment Utility
Not the best answer, but you can set the firewall to ignore entire IP blocks?

Country assigned blocks are here:

http://www.nirsoft.net/countryip/

That being said, you'll still get the traffic, and the firewall will still need to handle it (even if it's just ignoring it...)
0
 
LVL 4

Assisted Solution

by:Pancake_Effect
Pancake_Effect earned 167 total points
Comment Utility
The ISP can filter the IP range for you, thus diverting the problem before it even reaches you.

On your side however, the best way to manage it is to install a firewall box on the network. You can prevent some common DDOS attacks by blocking certain ports and turning off pings to the device. On a Cisco 5510 for example you can set it up to detect such things as well to help prevent issues. That however won't stop a DDOS attack overall, it will still spend it's resources trying to block it. That's why if it's a active DDOS attack I would call the ISP to block the IP range.
0
 
LVL 25

Assisted Solution

by:Tony Giangreco
Tony Giangreco earned 166 total points
Comment Utility
I suggest contacting your ISP. normally unless you have an enterprise type account, they won't do much. We use Sonicwall and their Geo-IP filter which allows us to block all foreign countries. You might want to look into a Cisco option that does the same.

You might also try moving to a new IP and putting it into stealth mode with Ping turned off so they can't detect you as easily.

Hope this helps!
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
Envision that you are chipping away at another e-business site with a team of pundit developers and designers. Everything seems, by all accounts, to be going easily.
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now